Security

You are describing how your company really works. Here is how that is protected.

rheAI holds your processes, risks, controls and evidence. This page states how the product is built, and shows the live technical verification of the deployment you are looking at right now.

Live deployment verification

Read from the hosting platform each time this page loads — not typed by us.

Reading…

Checking the running deployment.

Who is responsible for what

rheAI helps you describe and organise your own internal control. It does not perform your controls for you, and it does not give an assurance opinion.

rheAI is responsible for

  • Keeping your workspace separated, available and backed up.
  • Keeping evidence files private and access recorded.
  • Being clear about how suggestions were produced.

You are responsible for

  • Whether the described processes, risks and controls are accurate.
  • Actually performing the controls and keeping the evidence.
  • Appointing an independent practitioner if you need an opinion.

Every workspace is separated at the database

Each record belongs to exactly one organisation, and the database refuses any read or write that crosses that line — the rule is enforced below the application, not by application code that could be bypassed.

A signed-in member only ever reaches data for the organisation they belong to, and only with the role they were given.

Evidence files sit in private storage

Uploaded evidence is stored in private buckets. There is no public URL: files are reached through short-lived links generated for a member of your workspace at the moment they open the file.

Anything you deliberately share with an auditor is a read-only link you can revoke.

Sign-in and two-factor

Sign-in is email and password, with password reset by verified email link.

Two-factor authentication with an authenticator app can be switched on per account under Settings. It is available to everyone and not forced on anybody.

Changes are recorded

Creating, editing or deleting a readiness record writes an audit-log entry with the actor and the time. Views of an auditor link are recorded too.

That trail is part of what makes the material you hand over reviewable.

Privileged keys never reach the browser

The browser only ever holds the public project identifier and the publishable key. Privileged server credentials are read on the server, inside the function that needs them.

The workspace ships with an isolation check the team runs against the running build to confirm cross-organisation reads and file access are refused.

What we do not claim

rheAI has not told you it holds any certification, and this page makes no compliance or audit statement. Where you need one, an independent practitioner has to make it.

If your buyer needs something specific in writing, ask us and we will answer it plainly.

Reporting a security issue

If you believe you have found a vulnerability, tell us before disclosing it anywhere else. Include what you did, what you saw and roughly when. We will confirm we received it and keep you updated while we look into it.

Related: Privacy · Terms