Trust

Trust Centre

RiskAlign™ is operated by RegAlign Limited (Jersey company no. 165263). This page lists the security, data-protection, business-continuity and AI-use documents we hand to a prospect’s security or legal team in the first conversation. The pilot-stage versions are what is true today; the trigger-tied roadmap names what comes next.

Most documents below are issued under NDA. To request a copy, email security@riskalign.app. Public-facing documents (Vulnerability Disclosure Policy, security.txt) are linked directly.

Posture today

  • Security & Data Protection One-Pager

    Available on request

    Pilot-stage posture summary: hosting, authentication, encryption in transit and at rest, RLS, audit logging, current limitations.

  • Security Roadmap

    Available on request

    What is live today and what is trigger-tied (MFA, hash-chain, pen test, SOC 2, ISO 27001). Roadmap statement, not a completion claim.

  • Known Limitations

    Open

    Current repository status register of what the build does and does not do. The approved Microsoft portfolio-readiness record remains authoritative for overall readiness.

Data protection

  • Sub-processor Register

    Available on request

    Every third party that processes customer data, with region and safeguards.

  • DPIA Template

    Available on request

    Template completed per customer before pilot go-live. Template only; not a completed assessment.

  • DPA Template

    Draft — available on request

    Draft Data Processing Addendum. Pending external legal review before signature.

  • Data Retention and Deletion Policy

    Available on request

    Default retention windows, exit and deletion timeline, audit residue.

  • Data Flow

    Available on request

    Text description of data movement (browser → edge → backend).

Continuity & assurance

  • Business Continuity Plan (Outline)

    Draft — available on request

    Outline plan with single-founder RTO/RPO and founder-unavailability protocol. Not a tested plan.

  • Penetration Test — Scope of Work

    Available on request

    Issuable scope for CREST-accredited testers. Scope only; no completed test report.

  • Support Statement

    Available on request

    Pilot-stage hours, severities, targets, escalation.

Security disclosure

  • Vulnerability Disclosure Policy

    Open

    How to report a security issue. Safe-harbour terms.

  • security.txt

    Open

    RFC 9116 disclosure pointer for automated scanners.

Inspect for yourself

  • CAIQ v4 (197 controls)

    Open

    Full CSA Consensus Assessments Initiative Questionnaire v4 — browse, filter, search, or download PDF / TSV.

  • Verify an audit envelope

    Open

    Paste any Spine audit envelope JSON — from RiskAlign or RegAlign — and confirm its SHA-256 and chain linkage. No account, no PII returned.

  • Auditor access

    Open

    Two paths for external auditors: instant public demo, or a named time-boxed seat on the pilot tenant.

  • Operational metrics

    Open

    Published pilot-stage metrics record — not independently monitored live uptime. Numbers are shown honestly and dated to the last published review.

  • Document register

    Open

    Every trust document with status (Public / On request / Under NDA) and last-reviewed date.

  • Platform status

    Open

    Published pilot-stage status record and incident log — not a real-time independently monitored status service.

  • Public API documentation

    Open

    Tenant-scoped read API for risks, controls, evidence and audit trail, plus inbound webhook slot. OpenAPI 3.1 spec available.

AI

  • AI Use Disclosure

    Open

    Where AI is used in the product, where it is not used, governance controls, opt-out.

Stage disclosure. RiskAlign is a pilot-stage product. We do not hold SOC 2 or ISO 27001 certification; both are trigger-tied (see the Security Roadmap). We publish trigger-tied milestones, not calendar dates, so prospects can hold us to the event that justifies each next step rather than a date we cannot keep.