Procurement Trust Pack
Everything a vendor-risk, procurement, or insurer team needs to evaluate RILLA Shield. One PDF, plus individual documents and a clear statement of what we hold today.
Last updated 2026-08-24. This pack is app-owned content maintained by RILLA Shield. It is not an independent certification.
What is in the pack
Security controls summary
Encryption, residency, authentication, RBAC, network, audit, backup, and AI handling.
Sub-processor list
Current vendors, data location, and purpose for every sub-processor.
DPA template
Counter-signable data processing addendum covering roles, security, breach, and deletion.
Penetration test summary
Internal red-team review complete. Independent third-party test scheduled.
SOC 2 Type 1 Readiness
Readiness pack (CC1–CC9) and audit roadmap included as appendix.
Certification roadmap
SOC 2 Type 1 targeted Q4 2026; Type 2 Q3 2027; ISO 27001 2027.
Controls status matrix
Standard procurement questions and where RILLA stands today.
| Control area | Status | Evidence |
|---|---|---|
| Data residency | Complete | Australia (ap-southeast-2) |
| Encryption in transit / at rest | Complete | TLS 1.2+ / AES-256 |
| MFA | Complete | TOTP available to all users |
| SAML SSO | Complete | Available on Business and Enterprise |
| Role-based access control | Complete | Owner, Admin, Approver, Viewer + RLS |
| Immutable audit logging | Complete | 12-month retention |
| Backups & recovery | Complete | Daily encrypted, 7-day PITR |
| Penetration testing | In progress | Internal complete; external scheduled |
| SOC 2 Type 1 | In progress | Readiness complete; audit targeted Q4 2026 |
| ISO 27001 | Roadmap | Targeted 2027 |
Individual documents
Procurement FAQ
Is RILLA Shield SOC 2 certified?
Not yet. SOC 2 Type 1 is in progress and targeted for Q4 2026. This page and the trust pack are honest about our current status and do not claim a certification we have not received.
Where is customer data stored?
All customer data is hosted in Australia (ap-southeast-2, Sydney) by Supabase. Sub-processors are listed with their region and purpose.
Does RILLA access bank accounts or move money?
No. RILLA connects read-only to accounting or job platforms to verify payee details. We do not log into bank accounts, initiate payments, or change supplier records.
Can we get a full SIG Lite or CAIQ?
Yes. Full SIG Lite and CAIQ responses are available under NDA. Email security@rillashield.app with your procurement checklist and we typically respond within one business day.
What is your incident notification commitment?
We notify affected customers without undue delay and within 72 hours of becoming aware of a breach affecting customer data.
Honest status disclaimer
This page is maintained by RILLA Shield to answer common procurement questions. It describes controls and compliance activities we operate today. It is not a SOC 2 report, ISO 27001 certificate, or any other independent attestation. Shared responsibility applies: we secure the platform; customers are responsible for their account hygiene, MFA enrollment, and proper use of approval workflows.
