Security

What we claim, and what we can show you

A vendor’s own site is the cheapest available evidence of how it treats security. Ours was not good enough, so this page states plainly which claims are currently backed by something you can verify.

Claims register

Certifications

Each of these appeared on the previous site as a badge with nothing behind it. They stay listed as not evidenced until the underlying document exists and can be produced on request.

Certification claims and their current evidence status
ClaimStatusWhat publication requires
ISO/IEC 27001Not evidencedClaimed on the previous site with no certificate reference. Publication here requires the certificate number, the issuing body, and the scope statement.
SOC 2 Type IINot evidencedClaimed on the previous site. Publication here requires the audit period, the auditor, and a report available under NDA.
AWS Partner statusNot evidencedPublication here requires a link to the entry in the AWS Partner directory.

Engagement terms

How we handle your data during an engagement

Production data stays in your environment

We do not copy production data out of your systems. Where realistic data is needed for development we generate synthetic or masked datasets inside your boundary. The specifics are written into the data processing agreement before work starts, not agreed informally afterwards.

Access is least-privilege and time-bounded

Engineers get the access their work requires, granted through your identity provider where you have one, and revoked at rolloff as a checklist item rather than an intention.

Your code stays yours

Repositories live in your organisation from the first commit. Infrastructure lives in your accounts. There is no component we host that you need to keep paying for to keep your system running.

How we run our own systems

Debug output is disabled in every environment reachable from the internet, error pages carry no framework internals, and every 5xx raises an alert rather than sitting undetected. We are stating this explicitly because the previous version of this site failed all three.

Disclosure

Reporting a vulnerability

If you find a security problem in anything we run, write to security@riseforge.io. We acknowledge reports within one business day and will keep you updated until it is resolved.

We will not pursue legal action against anyone reporting in good faith who avoids privacy violations, service degradation, and access to data beyond what is needed to demonstrate the issue.

Running a vendor security review?

Tell us what your review requires and we will tell you honestly what we can produce today and what is still in progress.