← Trust Center
Procurement

Procurement Trust Pack

Everything a vendor-risk, procurement, or insurer team needs to evaluate RILLA Shield. One PDF, plus individual documents and a clear statement of what we hold today.

Last updated 2026-08-24. This pack is app-owned content maintained by RILLA Shield. It is not an independent certification.

What is in the pack

Security controls summary

Encryption, residency, authentication, RBAC, network, audit, backup, and AI handling.

Sub-processor list

Current vendors, data location, and purpose for every sub-processor.

DPA template

Counter-signable data processing addendum covering roles, security, breach, and deletion.

Penetration test summary

Internal red-team review complete. Independent third-party test scheduled.

SOC 2 Type 1 Readiness

Readiness pack (CC1–CC9) and audit roadmap included as appendix.

Certification roadmap

SOC 2 Type 1 targeted Q4 2026; Type 2 Q3 2027; ISO 27001 2027.

Controls status matrix

Standard procurement questions and where RILLA stands today.

Control areaStatusEvidence
Data residencyCompleteAustralia (ap-southeast-2)
Encryption in transit / at restCompleteTLS 1.2+ / AES-256
MFACompleteTOTP available to all users
SAML SSOCompleteAvailable on Business and Enterprise
Role-based access controlCompleteOwner, Admin, Approver, Viewer + RLS
Immutable audit loggingComplete12-month retention
Backups & recoveryCompleteDaily encrypted, 7-day PITR
Penetration testingIn progressInternal complete; external scheduled
SOC 2 Type 1In progressReadiness complete; audit targeted Q4 2026
ISO 27001RoadmapTargeted 2027

Individual documents

Procurement FAQ

Is RILLA Shield SOC 2 certified?

Not yet. SOC 2 Type 1 is in progress and targeted for Q4 2026. This page and the trust pack are honest about our current status and do not claim a certification we have not received.

Where is customer data stored?

All customer data is hosted in Australia (ap-southeast-2, Sydney) by Supabase. Sub-processors are listed with their region and purpose.

Does RILLA access bank accounts or move money?

No. RILLA connects read-only to accounting or job platforms to verify payee details. We do not log into bank accounts, initiate payments, or change supplier records.

Can we get a full SIG Lite or CAIQ?

Yes. Full SIG Lite and CAIQ responses are available under NDA. Email security@rillashield.app with your procurement checklist and we typically respond within one business day.

What is your incident notification commitment?

We notify affected customers without undue delay and within 72 hours of becoming aware of a breach affecting customer data.

Honest status disclaimer

This page is maintained by RILLA Shield to answer common procurement questions. It describes controls and compliance activities we operate today. It is not a SOC 2 report, ISO 27001 certificate, or any other independent attestation. Shared responsibility applies: we secure the platform; customers are responsible for their account hygiene, MFA enrollment, and proper use of approval workflows.