Skip to content

SECURITY

Built like the data matters. Because it does.

Your discovery corpus is your institutional memory. We are building it with the controls a bank would expect — the founders shipped payments infrastructure before RICS.

RICS has not launched. The controls below are what we are building and commit to having in place at launch — not a running system you can audit today. The only personal data we hold right now is waitlist entries and contact-form messages. We would rather you knew the difference.

001 · ENCRYPTION

At launch: TLS 1.3 in transit, AES-256 at rest, keys rotated in a managed KMS and never held in application code. Today the only data we store is waitlist entries and contact-form messages — served over TLS and held in a managed database that encrypts at rest.

002 · ACCESS

At launch: workspace-scoped isolation, role-based permissions, and shared brief URLs that are unguessable and revocable at any time. SSO and enforced two-factor authentication are on the roadmap. None of it exists yet — there are no accounts, no logins, and nothing to sign in to.

003 · INTEGRITY

Tamper-evidence is a design requirement, not a shipped feature. The plan: every brief carries a hash chain, so the artefact you cite in a decision six months from now is provably the artefact that was generated. It is not built yet.

004 · OPERATIONS

At launch: least-privilege internal access, audit-logged and reviewed, with no standing founder access to customer content. Today the founders can read the waitlist and contact tables directly — there is no product data yet, and no access tier to pretend otherwise. We review a vendor before any personal data flows through it.

005 · CONTINUITY

At launch: encrypted daily backups with tested restores, point-in-time recovery for your corpus, and deletion requests that propagate to backups within 30 days. Today there is no corpus — only the waitlist and contact records, and we will delete your row on request.

006 · COMPLIANCE PATH

SOC 2 Type II is on the roadmap ahead of general availability. We hold no certifications and no third-party attestations today, and we will not claim otherwise. We are building to meet NDPR, GDPR and POPIA obligations, and we already apply their core principles — collect the minimum, state the purpose, delete on request — to the waitlist. A DPA and a published subprocessor list land before launch. See Data-handling.

Responsible disclosure

Found a vulnerability? Email security@rics.dev with steps to reproduce. We acknowledge within 24 hours, fix by severity with the most urgent first, and credit researchers who report in good faith. No legal action for good-faith research.

RICS ships to design partners in Q1 2027. If you want to be told when these controls are built rather than promised, join the waitlist.