Trust Centre

An assurance company should be able to show its own controls.

Everything your security, privacy and procurement reviewers usually ask for — in one place, with honest status on what is in place and what is planned.

Security

How the platform protects client records

Organisation isolation

Every record is separated by organisation inside the database itself, so one client's workspace cannot read another's.

Role-based access

Four client roles — initiative owner, analyst, executive and administrator — each limited to the actions their role needs.

Two-person integrity

Evidence can't be judged by its supplier, findings can't be closed by their author, and decisions can't be taken by their submitter. Administrator overrides are recorded.

Tamper-evident evidence

Each uploaded file is fingerprinted (SHA-256) before upload, so any later substitution is detectable.

Exportable audit trail

Changes, judgements and decisions are recorded with the person, time and reason, and administrators can export the trail to CSV or JSON.

Private file storage

Evidence files are held privately and released only to authorised members of the owning organisation.

Hosting, encryption and recovery details are set out in the Security & Architecture Whitepaper below.

Privacy

Your data stays yours

  • Client data is never used to train, retrain or fine-tune AI models.
  • You retain ownership of your records and can export them in open formats.
  • Deletion on written request after the subscription ends, as set out in the Privacy Addendum.
  • We do not sell personal information.

Read the full Privacy Notice or download the Data Privacy Addendum below.

Compliance status

What is in place, and what is planned

Australian Privacy Act 1988 & APPs
Aligned
Handled as described in our Privacy Notice.
Voluntary AI Safety Standard
Built in
Platform assessments map to its guardrails.
ISO/IEC 42001 & NIST AI RMF
Mapped
Controls cross-referenced for client reporting.
SOC 2 Type II
Planned
Not yet attested. Timing can be aligned to your procurement.
ISO/IEC 27001
Planned
Not yet certified.
Independent penetration test
Planned
Scheduled; summary shared under NDA once complete.
AI assurances

How we use AI inside an AI assurance platform

No training on your data

Nothing you enter or upload is used to improve any model, ours or a provider's.

Drafts, never decisions

AI suggestions are labelled drafts. A named person must accept them before they enter the record.

Humans hold accountability

AI cannot judge evidence, close findings or take readiness decisions.

Vulnerability reporting

Found a security issue? Tell us.

Email contact@raiready.com with "Security report" in the subject, a description, the steps to reproduce and any affected address.

  • We acknowledge reports and keep you updated while we investigate.
  • Please don't access other people's data, disrupt the service or disclose publicly before we've fixed it.
  • We won't pursue good-faith research that follows these guidelines.
Document vault

Download our security documentation

Public

Security & Architecture Whitepaper

Hosting, tenancy isolation, access control, two-person integrity, evidence fingerprinting, AI handling and recovery targets.

For: CISO, security and architecture reviewers

Public

Data Privacy Addendum & Zero-Training Guarantee

Commitments on model training, AI processing, human accountability, data residency, export and deletion.

For: Privacy, legal and procurement

Under NDA

Security Questionnaire Responses

Pre-completed answers to common vendor security questionnaire domains, for your third-party risk review.

For: Third-party risk and vendor assurance teams