Security

Built for sensitive compliance data.

ICT third-party risk data includes contracts, audit reports and supplier detail. We state plainly what is available today and what is planned, and we do not claim certifications we do not hold.

Status labels

Available or Enterprise.

Everything listed here is in production today. Enterprise means it is contracted rather than self-served.

Infrastructure Security

  • EU data hosting

    The database, authentication and every uploaded document are stored and processed in the European Union (Frankfurt), and do not leave it. Model-assisted review, when a workspace enables it, is performed by a sub-processor in the United States.

    Available
  • Hardened cloud infrastructure

    Managed cloud services with restricted network access and least-privilege service accounts.

    Available
  • External penetration testing

    Infrastructure and application testing is carried out by DossierSec, a specialist security firm, rather than in-house. DossierSec is under common ownership with Relynt, which we state plainly because testing by a related party is not independent testing and you should weigh it accordingly. Reports are available on request.

    Available

Encryption

  • Encryption in transit

    TLS for all traffic between clients, services and storage.

    Available
  • Encryption at rest

    Database and object storage encrypted at rest.

    Available

Tenant Isolation

  • Logical tenant isolation

    Every record is scoped to a workspace and enforced server-side.

    Available
  • Separate vendor portal scope

    Vendors only access the assessments and requests addressed to them.

    Available
  • Dedicated deployment

    Isolated environment for large institutions.

    Enterprise

Access Control

  • Role-based access control

    Four workspace roles: Organization Admin, Risk Manager, Analyst and Viewer. A Viewer can read everything in the workspace and change nothing.

    Available
  • Multi-factor authentication

    MFA available for all workspace users.

    Available
  • SSO / SAML

    Federated sign-in with your identity provider.

    Enterprise

Auditability

  • Audit logs

    Who changed what, when, across providers, assessments, evidence, risks and the Register.

    Available
  • Row-level lineage

    Every row of the Register names the records it was assembled from, and who last changed each one. Values are not traced to a specific evidence document.

    Available
  • Audit log export

    Download the whole trail as CSV, or have your SIEM pull it on a schedule with a workspace API key.

    Available

Backups

  • Automated backups

    Encrypted daily backups of the database, retained by the hosting provider.

    Available
  • Point-in-time recovery

    Restore to any moment rather than to the last nightly backup. Not switched on today: recovery is from the most recent daily backup.

    Planned
  • Documented restore testing

    A backup is restored into an empty database on a schedule and the copy is checked: every table present, every row count equal, every foreign key re-validated. The procedure and the latest result are available on request.

    Available

Data Retention

  • Deletion on request

    An Organization Admin can export the whole workspace as JSON and then permanently delete it, including all records and all member accounts, from Settings › Data & retention.

    Available
  • Configurable retention policies

    Set how long the audit trail, notifications and evidence documents are kept, from Settings › Data & retention. A nightly job enforces it; the regulatory record is never deleted by retention.

    Available
  • Legal hold

    Suspend retention for the workspace or one record type while litigation or a supervisory request is open. Placing and releasing a hold is itself recorded.

    Available

AI Data Handling

  • No training on customer data

    Documents and responses are processed to produce findings for your workspace only.

    Available
  • Workspace AI controls

    Model-assisted review is off for a new workspace until an Organization Admin turns it on, and can be switched off again at any time. With it off, review runs the rule-based pass only and no document or response text leaves the platform.

    Available
  • Human review required

    AI never changes compliance status without an explicit human decision.

    Available

Incident Management

  • Documented incident process →

    Severity classification, triage targets, containment, recovery, customer notification windows and post-incident review.

    Available
  • Contractual notification commitments

    Notification timelines agreed in the customer contract.

    Enterprise

Security documentation

  • Sub-processor list →

    Every third party that processes customer data, what reaches them and where they run it. Published, not available on request.

    Available
  • Security documentation pack

    Architecture and DPA available on request.

    Available

Have a security review to complete?

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.

Security: Protecting Compliance and Vendor Data | Relynt