Held to a higher bar.
You authorize us to attack your systems, and that earns us a higher trust bar than any other vendor in your stack. Here's our security posture, our guardrails, and how to report an issue in Rift itself.
On the path to verified
SOC 2 Type II
We're pursuing SOC 2 Type II ahead of launch, and will share the report and audit window with design partners under NDA as soon as it completes.
ISO 27001
An ISO 27001 information security management system is in progress; current scope shared on request.
We test ourselves
Before launch we're standing up recurring third-party testing, and we run Rift against Rift. We won't ask you to trust anything we haven't proven on ourselves.
How we keep autonomous safe
The same guardrails that protect your production are documented here in full, with the technical detail a security reviewer needs.
- ✓Scope-locking: agents physically cannot act outside authorized assets
- ✓Safe-by-default exploitation: proof without destruction
- ✓Production-aware throttling and quiet hours
- ✓Full, replayable action log for every engagement
Subprocessors & policies
Subprocessor list
Current third parties that process customer data, with purpose, updated as it changes.
Data Processing Addendum
Standard DPA available for signature during onboarding.
Privacy policy
How we handle personal data across the site and platform.
Security questionnaire
Pre-filled CAIQ / SIG to speed your vendor review.
Found a bug in Rift?
Before launch we're standing up a coordinated disclosure program with safe-harbor for good-faith research. If you've already found an issue in Rift itself, email us and we'll credit you.
Want our security package at launch?
We're standing up SOC 2 Type II and ISO 27001 ahead of launch, and we'll share the report and audit window with design partners under NDA as soon as it completes.