Country Risk Briefings are live — 10+ markets, refreshed continuously.Explore
Trust Center

Security, privacy and compliance — by design

Everything your security, legal and procurement teams need to evaluate RisQo: certifications, sub-processors, data residency, privacy posture and incident response.

Certifications & frameworks

RisQo is built and operated against internationally recognised standards. Reports and certificates are available under NDA.

Certified
ISO/IEC 27001

Information security management system across platform and operations.

Aligned
ISO/IEC 27701

Privacy information management extension built on ISO 27001 controls.

Certified
ISO 22301

Business continuity management for platform and customer-facing services.

Certified
ISO 9001

Quality management across product delivery and customer operations.

In progress
SOC 2 Type II

Security, availability and confidentiality — report Q4 2026.

Compliant
GDPR

EU/EEA data processing as both controller and processor, with DPA available.

Aligned
DORA-ready

ICT risk, incident reporting and third-party register for EU financial entities.

Aligned
AMLD6 / AMLR

KYB, UBO, sanctions and adverse-media workflows with audit trail.

Security controls

Defence-in-depth across our platform, people and processes.

Encryption

TLS 1.3 in transit and AES-256 at rest. Customer secrets sealed with envelope encryption and per-tenant keys.

Access control

SSO (SAML & OIDC), SCIM provisioning, role-based access, granular API scopes and short-lived tokens.

Monitoring & logging

24/7 SIEM, immutable audit logs, anomaly detection on auth and data-export events.

Vulnerability management

Continuous dependency scanning, quarterly external pen-tests and a coordinated disclosure programme.

Resilience

Multi-region active-active for the API tier. RPO ≤ 15 min, RTO ≤ 1 hour. DR exercises twice a year.

People security

Background checks, mandatory security training, least-privilege production access with break-glass auditing.

Privacy & GDPR

RisQo processes personal data lawfully, transparently and only where necessary for KYB, AML and risk-management purposes.

Lawful basis

Legitimate interest for KYB/AML processing; contract for customer accounts; consent for marketing.

Data subject rights

Access, rectification, erasure and objection handled within 30 days via privacy@risqo.ai.

International transfers

EU SCCs + Transfer Impact Assessments for any data leaving the EEA; UK Addendum where applicable.

Retention

Customer records retained per contract; AML evidence retained 5 years per AMLD obligations, then deleted.

Data Protection Officer: dpo@risqo.ai · EU representative available on request. Our DPA is available pre-signature on request.

Sub-processors

Current list of sub-processors engaged to deliver the RisQo service. Customers are notified of material changes 30 days in advance.

ProviderPurposeLocation
Amazon Web Services (AWS)Primary cloud infrastructureEU (Ireland, Frankfurt)
CloudflareEdge network, WAF and DDoS protectionGlobal edge
SupabaseManaged PostgreSQL, auth and storageEU (Frankfurt)
StripePayment processing and invoicingEU & US
ResendTransactional email deliveryEU & US
SentryError and performance monitoringEU
DatadogInfrastructure and application observabilityEU
LinearEngineering ticketing and incident trackingUS

Subscribe to sub-processor updates at trust@risqo.ai.

Data residency

EU

Default residency for customer data in Frankfurt with EU-only sub-processors where elected.

UK

Available on request for UK financial-services customers under UK GDPR.

UAE / MENA

Regional residency available via Dubai region for in-scope customers.

Incident response

< 1h
Internal triage & severity assignment
< 24h
Customer notification for material incidents
< 72h
Regulatory notification where GDPR/DORA applies
Post-mortem
Root-cause analysis shared with affected customers

Live status: status.risqo.ai · Security contact: security@risqo.ai

Responsible disclosure

If you believe you've found a vulnerability, please email security@risqo.ai with a description and reproduction steps. We acknowledge within 2 business days and will not pursue legal action for good-faith research that respects user privacy and service availability.

Our /.well-known/security.txt contact channel is monitored 24/7.

Documents available on request

ISO 27001 certificate & Statement of Applicability
ISO 22301 / 9001 certificates
Latest penetration test executive summary
Data Processing Agreement (DPA)
Standard Contractual Clauses (SCCs)
Business continuity & DR summary
Information security policy summary
Vendor security questionnaire (CAIQ / SIG Lite)
DORA register of information template