You are telling us where your security is weak. Here is how we protect that.
All data stays in the EU. The database is hosted in Ireland, and sign-in emails are delivered from the EU as well. Data is encrypted at rest by the platform and in transit with TLS 1.3.
This matters, so we are explicit about it: your assessment answers, scores and gaps are never sent to any external AI or language-model provider. Your recommendations come from a fixed, rule-based library that we wrote — the same low score always produces the same advice. There is no generative model in the assessment path.
Every record belongs to exactly one organisation. Which organisation you belong to is resolved on the server from your login session — never from anything your browser sends — and every query is filtered by it. The database additionally enforces row-level security as a second, independent barrier, so a coding mistake alone cannot expose another customer's data.
We reviewed this specifically, including attempts to reach another organisation's data by tampering with requests. No cross-tenant access was possible.
SelfSec is invite-only — open sign-up is disabled. Sign-in uses a one-time link sent to your email address, so there is no password for us to store or for you to lose.
Your saved reports are not published at a public address. A report can only be opened by someone signed in to your organisation, and that is enforced by the database itself through row-level security — not only by application code. Someone outside your organisation who somehow obtained the URL still gets nothing.
To share a report outside your organisation — with your board, an auditor or a client — open it and use Download PDF. You then control exactly who receives it, through your own channels.
We keep the list short on purpose. There are two, both in the EU:
Nobody else. We use no analytics, advertising or session-recording tools. The named list is available in our data processing agreement (DPA) on request.
We keep your assessments for as long as your account is active, so you can track progress over time. You can ask us to delete your organisation's data at any time by emailing support@rycode.io, and we will confirm once it is done. A data processing agreement (DPA) is available on request.
We would rather tell you this than let you assume it. There is no customer-facing audit log yet, and we have not undergone an external security audit or ISO 27001 certification.
If you find a security problem, please email support@rycode.io. We will acknowledge it and keep you updated on the fix.