Trust

Document register

Every governance, security and data-protection document we have, with its current status and the month it was last reviewed. Anything markedOn requestorUnder NDAis issued by emailing security@riskalign.app.

DocumentStatusLast reviewedAccess
Security & Data Protection One-Pager
Honest pilot-stage posture summary — hosting, auth, encryption, RLS, audit, open issues.
On requestJun 2026Request
Trust Pack (Master)
Combined evidence pack issued to security and procurement teams during pilot scoping.
Under NDAJun 2026Request
CAIQ v4 — 197 controls
CSA Consensus Assessments Initiative Questionnaire v4, Level 1 self-assessment.
PublicJun 2026Open
Sub-processor register
Every third party that processes customer data, with region and safeguards.
On requestJun 2026Request
Data Processing Addendum (DPA) — template
Draft DPA. Pending external legal review before signature; redlines welcome.
On requestJun 2026Request
Data Protection Impact Assessment (DPIA) — template
Per-customer DPIA completed before any pilot go-live.
On requestJun 2026Request
Data retention & deletion policy
Default retention windows, exit and deletion timeline, audit residue.
On requestJun 2026Request
Business Continuity Plan — outline
Honest single-founder RTO/RPO and founder-unavailability protocol.
On requestJun 2026Request
Penetration test — scope of work
Issuable scope for a CREST-accredited tester. Test itself is deferred (see /trust/metrics).
On requestJun 2026Request
AI Use Disclosure
Where AI is used in the product, where it is not used, governance controls, opt-out.
PublicJun 2026Open
Vulnerability Disclosure Policy
How to report a security issue. Safe-harbour terms.
PublicJun 2026Open
Known limitations register
Single-source register of what the build does not do.
PublicJun 2026Open

This register is maintained by RegAlign Limited (Jersey company no. 165263) as operator of RiskAlign™. It is reviewed at least quarterly and whenever a document changes.