Security by architecture

Enterprise risk data deserves enterprise isolation.

Risk Vault layers tenant boundaries, identity controls, fine-grained authorization, encryption, and audit records around the data that informs consequential decisions.

Tenant isolation

A defined security boundary.

Deployment options can provide an isolated application and data environment, including models hosted in a customer-controlled AWS account or a managed single-tenant environment, subject to the selected offering.

Security architecture diagram neededDedicated tenant boundary around application, database, object storage, background services, and encryption.
01

Identity & access

External identity providers, local-account MFA, roles, policies, claims, and record-aware authorization work together.

02

Encryption & key control

Protect data in transit and at rest, with supported key-management choices aligned to the deployment architecture.

03

Auditable operations

Capture security-relevant actions, workflow history, integration events, and administrative changes for oversight.

04

Permission-aware outputs

Apply access rules to screens, counts, dashboards, reports, exports, APIs, and background delivery—not only navigation.

05

Controlled integrations

Use signed webhooks, protected credentials, monitored delivery, and scoped integration administration.

06

Data-conscious assistance

AI-enabled capabilities can be deployed with privacy-conscious model choices appropriate to the approved environment and configuration.

Security review

Bring your requirements.

Architecture, key management, identity provider support, retention, logging, monitoring, recovery, and assurance materials should be evaluated against the deployment option and product release under consideration.

Contact us for the current security overview and technical review materials.

Contact security