What every badge means.
We only show claims we can back up. These are self-issued factual statements about our controls and infrastructure. No third-party logos or trademarks are used without written permission.
Australian-hosted data
All customer data is stored in the ap-southeast-2 (Sydney) region. We do not offshore primary data processing for Australian customer accounts.
Essential 8 aligned
We are implementing the Australian Cyber Security Centre (ACSC) Essential Eight mitigation strategies. “Aligned” means we are actively working toward the controls, not that we hold a formal government certification.
SOC 2 Type 1 ready
Our SOC 2 Type 1 Readiness Pack is complete and available for procurement and insurer due diligence. A full Type 1 attestation is targeted for Q1 2027.
MFA + audit log
TOTP MFA is available on every account. Every authentication, supplier change, approval decision, and evidence-pack export is written to an immutable audit log.
Invoice fraud detection
RILLA detects Business Email Compromise (BEC), payment redirection, altered invoice details, spoofed sender domains, and changed supplier bank details.
Risk rating in 10 seconds
Manual scans return a Safe, Verify, or High Risk risk rating with explained reasons in under 10 seconds for typical invoices and emails.
Decision support only
RILLA Shield returns risk scores and forensic evidence to help you make your own informed decisions. It is not financial, legal, insurance, credit, tax, or accounting advice, and never a recommendation to pay or refuse to pay.
256-bit SSL secure
All traffic to and from RILLA Shield is encrypted with TLS/HTTPS. We do not accept insecure connections and our security.txt is published at /.well-known/security.txt.
Australian owned & operated
RILLA Shield is built, run and supported from Australia. Our data processing, customer support and trust pack are geared for Australian businesses, laws and regulators.
Honest badge policy
We never claim a certification we do not hold. “Aligned” and “ready” are not the same as “certified”. If a badge status changes, we update this page immediately.
Partner & third-party logos
We only show logos with permission
Adding a third-party logo (e.g. Lawpath, an insurer, a bank) requires their written approval. Paying for a service or being in discussions does not automatically grant trademark or logo rights.
If a partner agrees, we add their logo here with a clear label such as “Legal partner” or “Technology partner”. Until then, we leave the space empty so we never imply an endorsement that doesn’t exist.
Ask your Lawpath contact before adding their logo.
No logo used until a formal agreement is signed.
How to ask Lawpath for a logo
Send a short email to your Lawpath contact:
“Hi [Name], RILLA Shield is building a public trust page and would love to list Lawpath as a legal/compliance partner with a small badge. We’re happy to link back to Lawpath and use any approved logo format. Could you confirm if this is OK, or send me your partner-branding guidelines?”
Need proof for a procurement team?
Email security@rillashield.app and we’ll send the full trust pack, including the SOC 2 readiness pack, DPA, and sub-processor list.
Show buyers you're verified. Embed the badge.
Paste this on your website, invoice footer, or quote template. It pulls your live RILLA Shield trust score by ABN and links back to your verification page.
<div data-rilla-shield-abn="YOUR_ABN"></div> <script async src="https://rillashield.app/api/public/trust/badge.js"></script>
Replace YOUR_ABN with your 11-digit ABN. The badge auto-updates when your trust level changes. Raw JSON is available at GET /api/public/trust/<abn> for custom integrations.