Skip to main content
    Security

    Your documents stay yours.

    RiskRemedy is built with the security requirements of commercial insurance professionals in mind. This page describes how we handle your data, the controls we have in place, and what documentation we make available to procurement teams.

    At a glance

    The short version

    Hosting
    United States (AWS)
    Data at rest
    AES-256 (S3, MongoDB Atlas)
    Data in transit
    TLS 1.2+
    Tenant isolation
    Per-tenant scoping on every query
    Model training on your data
    Never
    Authentication
    AWS Cognito with TOTP multi-factor authentication
    Audit logs
    User-level, available to admins
    Data residency
    United States
    Commitments

    How we handle your data

    01
    Encryption everywhere

    Every document transmitted to and stored within RiskRemedy is encrypted in transit (TLS 1.2+) and at rest (AES-256). Object storage runs in AWS S3 with server-side encryption; our application database runs in MongoDB Atlas with encryption at rest enabled.

    02
    Per-tenant data isolation

    Your documents, analyses, and reports are never commingled with any other company's data. Tenant access is validated on every authenticated request, and customer data is logically segregated and accessed only through tenant-scoped queries.

    03
    No model training on your data

    Your documents are never used to train, fine-tune, or improve any model, ours or anyone else's. We use Anthropic and Google as our large language model providers; under their current standard API terms, customer-submitted data on paid API usage is not used to train their models.

    04
    Granular access controls

    User accounts are scoped to a single tenant (or, for admins, an explicit list of tenants). Roles control what each user can see and do. User-level audit logs are available to administrators.

    05
    Public access blocked by default

    All S3 buckets have public access blocks enabled at four levels (ACLs and policies, both new and existing). The only way to retrieve a document is through an authenticated, short-lived presigned URL issued by our backend.

    Sub-processors

    Who else touches your data

    We use the following sub-processors to operate the platform. Each operates under written agreements that restrict their use of customer data to providing services to us. We will provide reasonable advance notice on this page before adding new sub-processors that process customer data.

    ProviderPurpose
    Amazon Web ServicesCompute (ECS), object storage (S3), email delivery (SES), identity (Cognito)
    MongoDB AtlasPrimary application database
    AnthropicLarge language model API
    Google (Gemini API)Large language model API
    LangSmithLLM pipeline observability and tracing
    Access controls

    Authentication, sessions, and internal access

    Authentication

    RiskRemedy uses AWS Cognito for identity. User accounts are created by tenant administrators; there is no public self-signup for the dashboard. TOTP-based multi-factor authentication is available to all users.

    Session tokens

    Access and ID tokens are short-lived, and refresh tokens expire daily, requiring regular re-authentication.

    Internal access

    Production access is restricted to a minimal set of engineering staff under least-privilege IAM roles. We do not access customer documents except as needed to investigate a specific support request, security incident, or as required by law.

    Incident response

    Reporting and disclosure

    Found a vulnerability?

    Please report it to security@riskremedy.io. We commit to acknowledging reports within two business days and will not pursue legal action against researchers acting in good faith.

    If we have an incident

    In the event of a confirmed security incident affecting your data, we will notify the relevant tenant administrators without undue delay, consistent with applicable law and the terms of your customer agreement. Our incident response process covers identification, containment, eradication, recovery, and post-incident review.

    Compliance roadmap

    Certifications and posture

    SOC 2

    SOC 2 Type I is in progress. We're happy to share our auditor, scope, and target completion date under NDA — reach out via the procurement form below.

    GDPR and CCPA

    When processing customer data on behalf of a customer, RiskRemedy acts as a processor under GDPR and a service provider under CCPA. A Data Processing Addendum (DPA) is available on request.

    Need documentation for procurement?

    We make the following available on request, under NDA where appropriate: Data Processing Addendum (DPA), sub-processor list with change history, and a completed security questionnaire (SIG-Lite / CAIQ-Lite).

    Request documentation

    Last updated: May 26, 2026