Organisation isolation
Every record is separated by organisation inside the database itself, so one client's workspace cannot read another's.
Everything your security, privacy and procurement reviewers usually ask for — in one place, with honest status on what is in place and what is planned.
Every record is separated by organisation inside the database itself, so one client's workspace cannot read another's.
Four client roles — initiative owner, analyst, executive and administrator — each limited to the actions their role needs.
Evidence can't be judged by its supplier, findings can't be closed by their author, and decisions can't be taken by their submitter. Administrator overrides are recorded.
Each uploaded file is fingerprinted (SHA-256) before upload, so any later substitution is detectable.
Changes, judgements and decisions are recorded with the person, time and reason, and administrators can export the trail to CSV or JSON.
Evidence files are held privately and released only to authorised members of the owning organisation.
Hosting, encryption and recovery details are set out in the Security & Architecture Whitepaper below.
Read the full Privacy Notice or download the Data Privacy Addendum below.
Nothing you enter or upload is used to improve any model, ours or a provider's.
AI suggestions are labelled drafts. A named person must accept them before they enter the record.
AI cannot judge evidence, close findings or take readiness decisions.
Email contact@raiready.com with "Security report" in the subject, a description, the steps to reproduce and any affected address.
Hosting, tenancy isolation, access control, two-person integrity, evidence fingerprinting, AI handling and recovery targets.
For: CISO, security and architecture reviewers
Commitments on model training, AI processing, human accountability, data residency, export and deletion.
For: Privacy, legal and procurement
Pre-completed answers to common vendor security questionnaire domains, for your third-party risk review.
For: Third-party risk and vendor assurance teams