Built for sensitive compliance data.
ICT third-party risk data includes contracts, audit reports and supplier detail. We state plainly what is available today and what is planned, and we do not claim certifications we do not hold.
Status labels
Available or Enterprise.
Everything listed here is in production today. Enterprise means it is contracted rather than self-served.
Infrastructure Security
- Available
EU data hosting
The database, authentication and every uploaded document are stored and processed in the European Union (Frankfurt), and do not leave it. Model-assisted review, when a workspace enables it, is performed by a sub-processor in the United States.
- Available
Hardened cloud infrastructure
Managed cloud services with restricted network access and least-privilege service accounts.
- Available
External penetration testing
Infrastructure and application testing is carried out by DossierSec, a specialist security firm, rather than in-house. DossierSec is under common ownership with Relynt, which we state plainly because testing by a related party is not independent testing and you should weigh it accordingly. Reports are available on request.
Encryption
- Available
Encryption in transit
TLS for all traffic between clients, services and storage.
- Available
Encryption at rest
Database and object storage encrypted at rest.
Tenant Isolation
- Available
Logical tenant isolation
Every record is scoped to a workspace and enforced server-side.
- Available
Separate vendor portal scope
Vendors only access the assessments and requests addressed to them.
- Enterprise
Dedicated deployment
Isolated environment for large institutions.
Access Control
- Available
Role-based access control
Four workspace roles: Organization Admin, Risk Manager, Analyst and Viewer. A Viewer can read everything in the workspace and change nothing.
- Available
Multi-factor authentication
MFA available for all workspace users.
- Enterprise
SSO / SAML
Federated sign-in with your identity provider.
Auditability
- Available
Audit logs
Who changed what, when, across providers, assessments, evidence, risks and the Register.
- Available
Row-level lineage
Every row of the Register names the records it was assembled from, and who last changed each one. Values are not traced to a specific evidence document.
- Available
Audit log export
Download the whole trail as CSV, or have your SIEM pull it on a schedule with a workspace API key.
Backups
- Available
Automated backups
Encrypted daily backups of the database, retained by the hosting provider.
- Planned
Point-in-time recovery
Restore to any moment rather than to the last nightly backup. Not switched on today: recovery is from the most recent daily backup.
- Available
Documented restore testing
A backup is restored into an empty database on a schedule and the copy is checked: every table present, every row count equal, every foreign key re-validated. The procedure and the latest result are available on request.
Data Retention
- Available
Deletion on request
An Organization Admin can export the whole workspace as JSON and then permanently delete it, including all records and all member accounts, from Settings › Data & retention.
- Available
Configurable retention policies
Set how long the audit trail, notifications and evidence documents are kept, from Settings › Data & retention. A nightly job enforces it; the regulatory record is never deleted by retention.
- Available
Legal hold
Suspend retention for the workspace or one record type while litigation or a supervisory request is open. Placing and releasing a hold is itself recorded.
AI Data Handling
- Available
No training on customer data
Documents and responses are processed to produce findings for your workspace only.
- Available
Workspace AI controls
Model-assisted review is off for a new workspace until an Organization Admin turns it on, and can be switched off again at any time. With it off, review runs the rule-based pass only and no document or response text leaves the platform.
- Available
Human review required
AI never changes compliance status without an explicit human decision.
Incident Management
- Available
Severity classification, triage targets, containment, recovery, customer notification windows and post-incident review.
- Enterprise
Contractual notification commitments
Notification timelines agreed in the customer contract.
Security documentation
- Available
Every third party that processes customer data, what reaches them and where they run it. Published, not available on request.
- Available
Security documentation pack
Architecture and DPA available on request.
Have a security review to complete?
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.