Trust · Security · Compliance
All systems operational

The security posture behind every risk we manage.

RiskEye is engineered to the same standards we help our customers report against. This page captures how we protect your data, the certifications we hold, and how we operate in production.

Certifications

SMB1001 Gold Level 3
Active
SMB1001
Gold · Level 3 · Cybercert

The Australian small-business cyber-security standard. Gold Level 3 represents the top tier — covering identity, endpoint, backup, and incident-response controls independently verified by Cybercert.

Verify at cybercert.com.au →
CIS
CONTROLS
Active
CIS Controls
Center for Internet Security · v8

The industry-standard prioritised set of 18 defensive controls, mapped to every major framework we support (NIST CSF, ISO 27001, Essential 8). Our internal environment is operated to CIS v8 IG2 baseline.

Learn about CIS Controls →

Encryption & Access

In transit

TLS 1.3 only. HSTS with a 2-year max-age and preload. Modern-cipher suite floor, no weak-cipher fall-back.

TLS 1.3 · HSTS 2y preload
At rest

MongoDB AES-256 volume encryption. Passwords bcrypt-hashed. Reset tokens SHA-256. Invitation tokens HMAC + Fernet. TOTP secrets Fernet-encrypted.

AES-256 · bcrypt · Fernet
Access

TOTP two-factor is required on every sign-in. Ten one-time recovery codes issued at enrolment. Role-based access with default-deny. Rate-limit + lockout on failed sign-ins.

TOTP · RBAC · Lockout

System status · Last 90 days

API
100% uptime · 1 day monitored
Operational
90 days agoToday
Database
100% uptime · 1 day monitored
Operational
90 days agoToday
Email delivery
100% uptime · 1 day monitored
Operational
90 days agoToday

Incident feed · 90 days

No incidents in the last 90 days.
Any confirmed availability, security or data incident will appear here alongside its post-mortem link. Last checked: 21/09/2026 09:04.

Assurance

Multi-tenancy
Every record is tenant-scoped at the repository layer. Super-admin cross-tenant access is opt-in and audit-logged on every switch.
Hash-chained audit
Every mutation appends a SHA-256-chained audit event. Tampering with any historic entry breaks the chain and is detected on export.
Reports integrity
Snapshot PDFs embed a SHA-256 integrity hash. Regenerating from the frozen snapshot reproduces byte-identical output.
Least privilege
Default-deny RBAC matrix. PATCH endpoints enforce a per-role field allow-list, so a compromised viewer token can't escalate.
Suspension controls
Users and whole tenants can be suspended from the super-admin console; suspended principals are blocked on every authed request, not just at login.