Security & Trust
Built for firms who carry other people’s compliance.
If you run GRC for several clients, one tenant leaking into another ends your practice. RisQore is engineered so that cannot happen, and so you can prove it to the clients and auditors who ask. This page states exactly what is in place today, and what is still on the way. No claimed certification we do not hold.
Tenant isolation, the part your business depends on
Every client lives in its own workspace under your firm. Access is enforced in the application on every request: a partner can only reach workspaces that belong to their own firm, a client user can only reach their own workspace, and the check fails closed. This is not a sample of routes, it is the whole surface.
✓A single authoritative scope gate guards every client-workspace page and mutation, verifying ownership before any data is read or written.
✓An automated coverage test discovers every one of our API routes and fails the build if any tenant route ships without a scope check, so an unscoped endpoint cannot reach production unnoticed.
✓Defense in depth: row-level security policies and tenant foreign-key constraints sit beneath the application checks at the database layer.
✓The public REST API resolves each key to one firm and filters every query to that firm; a key cannot read another firm’s data.
Authentication and access
✓Identity is handled by a dedicated authentication provider, with email and password plus Google and Microsoft sign-in, and multi-factor authentication available.
✓Role-based access with least-privilege defaults: owner, member, auditor, and client roles, each scoped to what it needs.
✓Enterprise single sign-on for your own team is available on the Enterprise tier.
Data protection
✓Encryption in transit: TLS for all traffic, HTTP Strict Transport Security enforced, a strict Content Security Policy, and clickjacking protection.
✓Encryption at rest through managed, access-controlled Postgres hosting.
✓A 30-day soft-delete recovery window protects against accidental loss, with permanent deletion on request.
Auditability
Every meaningful action is recorded with the actor, the affected record, a before-and-after change snapshot, timestamp, IP address, and user agent. The trail is scoped per firm and per client, so it is usable in your client’s own audit, and database-level audit triggers back the application log.
Your data stays yours
✓Export controls, risks, policies, and cross-framework gaps from each workspace; CSV import and export on Pro and above.
✓A documented DPA with a full sub-processor list is provided, so you can extend your own processing chain to your clients with confidence.
✓Offboarding removes a firm’s data on request; there is no hostage clause.
What is in progress, stated plainly
SOC 2 Type II and ISO 27001 for RisQore itself are on the roadmap, not yet certified. An independent penetration test focused on tenant isolation, our DPA, sub-processor list, and the current security package are available to prospects under NDA. We would rather tell you this directly than let you find the gap yourself, because you do the same for your clients.
Request the security package, the DPA, or a tenant-isolation walkthrough.
Contact security← Back to RisQore