// Trust Center

Held to a higher bar.

You authorize us to attack your systems, and that earns us a higher trust bar than any other vendor in your stack. Here's our security posture, our guardrails, and how to report an issue in Rift itself.

// Certifications

On the path to verified

SOC 2 Type II (in progress)ISO 27001 (in progress)GDPR (in progress)Third-party pen-test (planned)

SOC 2 Type II

We're pursuing SOC 2 Type II ahead of launch, and will share the report and audit window with design partners under NDA as soon as it completes.

ISO 27001

An ISO 27001 information security management system is in progress; current scope shared on request.

We test ourselves

Before launch we're standing up recurring third-party testing, and we run Rift against Rift. We won't ask you to trust anything we haven't proven on ourselves.

// Guardrails

How we keep autonomous safe

The same guardrails that protect your production are documented here in full, with the technical detail a security reviewer needs.

  • Scope-locking: agents physically cannot act outside authorized assets
  • Safe-by-default exploitation: proof without destruction
  • Production-aware throttling and quiet hours
  • Full, replayable action log for every engagement
Data handling
Storage
Findings and evidence encrypted at rest; ephemeral options for sensitive engagements.
Residency
Stored in a single managed region today; configurable residency, single-tenant, and self-hosted are on the roadmap.
Training
We never train models on your data.
Retention
Defined retention windows, with data removed on offboarding.
// Documents

Subprocessors & policies

Subprocessor list

Current third parties that process customer data, with purpose, updated as it changes.

Data Processing Addendum

Standard DPA available for signature during onboarding.

Privacy policy

How we handle personal data across the site and platform.

Security questionnaire

Pre-filled CAIQ / SIG to speed your vendor review.

// Disclosure

Found a bug in Rift?

Before launch we're standing up a coordinated disclosure program with safe-harbor for good-faith research. If you've already found an issue in Rift itself, email us and we'll credit you.

[email protected] PGP key & policy on the live page

Want our security package at launch?

We're standing up SOC 2 Type II and ISO 27001 ahead of launch, and we'll share the report and audit window with design partners under NDA as soon as it completes.