Trust
Trust Centre
RiskAlign™ is operated by RegAlign Limited (Jersey company no. 165263). This page lists the security, data-protection, business-continuity and AI-use documents we hand to a prospect’s security or legal team in the first conversation. The pilot-stage versions are what is true today; the trigger-tied roadmap names what comes next.
Most documents below are issued under NDA. To request a copy, email security@riskalign.app. Public-facing documents (Vulnerability Disclosure Policy, security.txt) are linked directly.
Posture today
Security & Data Protection One-Pager
Available on requestPilot-stage posture summary: hosting, authentication, encryption in transit and at rest, RLS, audit logging, current limitations.
Security Roadmap
Available on requestWhat is live today and what is trigger-tied (MFA, hash-chain, pen test, SOC 2, ISO 27001). Roadmap statement, not a completion claim.
Known Limitations
OpenCurrent repository status register of what the build does and does not do. The approved Microsoft portfolio-readiness record remains authoritative for overall readiness.
Data protection
Sub-processor Register
Available on requestEvery third party that processes customer data, with region and safeguards.
DPIA Template
Available on requestTemplate completed per customer before pilot go-live. Template only; not a completed assessment.
DPA Template
Draft — available on requestDraft Data Processing Addendum. Pending external legal review before signature.
Data Retention and Deletion Policy
Available on requestDefault retention windows, exit and deletion timeline, audit residue.
Data Flow
Available on requestText description of data movement (browser → edge → backend).
Continuity & assurance
Business Continuity Plan (Outline)
Draft — available on requestOutline plan with single-founder RTO/RPO and founder-unavailability protocol. Not a tested plan.
Penetration Test — Scope of Work
Available on requestIssuable scope for CREST-accredited testers. Scope only; no completed test report.
Support Statement
Available on requestPilot-stage hours, severities, targets, escalation.
Security disclosure
Inspect for yourself
CAIQ v4 (197 controls)
OpenFull CSA Consensus Assessments Initiative Questionnaire v4 — browse, filter, search, or download PDF / TSV.
Verify an audit envelope
OpenPaste any Spine audit envelope JSON — from RiskAlign or RegAlign — and confirm its SHA-256 and chain linkage. No account, no PII returned.
Auditor access
OpenTwo paths for external auditors: instant public demo, or a named time-boxed seat on the pilot tenant.
Operational metrics
OpenPublished pilot-stage metrics record — not independently monitored live uptime. Numbers are shown honestly and dated to the last published review.
Document register
OpenEvery trust document with status (Public / On request / Under NDA) and last-reviewed date.
Platform status
OpenPublished pilot-stage status record and incident log — not a real-time independently monitored status service.
Public API documentation
OpenTenant-scoped read API for risks, controls, evidence and audit trail, plus inbound webhook slot. OpenAPI 3.1 spec available.
AI
AI Use Disclosure
OpenWhere AI is used in the product, where it is not used, governance controls, opt-out.
Stage disclosure. RiskAlign is a pilot-stage product. We do not hold SOC 2 or ISO 27001 certification; both are trigger-tied (see the Security Roadmap). We publish trigger-tied milestones, not calendar dates, so prospects can hold us to the event that justifies each next step rather than a date we cannot keep.