This register separates what the current release candidate proves, what depends on service configuration, what is only partially complete, and what is still planned. Production deployment and independent assurance are never implied by source code alone.
Evidence snapshot reviewed 2 September 2026
How to read the evidence level
Verified release candidate
Passed isolated code, database, and browser validation. Production proof remains separate.
Service configuration
Documented service or provider configuration. Live operational attestation remains separate.
Implemented with limitations
A useful control exists, but an enterprise limitation remains open.
Not yet available
Not available today and not presented as a current control.
Client tenant isolation
Verified release candidate
Every client request is resolved through a fail-closed application scope before tenant data is read or changed.
Evidence available
Central page, action, API, AI, export, and file gates passed sibling-tenant negative tests against disposable PostgreSQL.
Limitation
This is isolated release-candidate evidence. Production migration, deployment, and live traffic verification remain separate gates.
Role and identity lifecycle
Verified release candidate
Partner, client, contributor, viewer, and auditor authority is enforced on the server, with expiring invitations and immediate deprovisioning.
Evidence available
Five-role Clerk browser journeys and PostgreSQL invitation lifecycle tests cover assignment, expiry, resend, revoke, replay prevention, role change, and deprovisioning.
Limitation
This is isolated release-candidate evidence, not production proof. Enterprise SAML/OIDC SSO, SCIM, conditional access, and tenant-wide mandatory MFA are not available yet.
Web transport protection
Implemented with limitations
The current application config defines CSP, frame protection, content-type protection, referrer policy, permissions policy, and production HSTS headers.
Evidence available
The controls are defined in the versioned Next.js response-header configuration and checked during the release build.
Limitation
A source configuration is not live-domain proof. The deployed response headers must be checked after each production release.
Application auditability
Implemented with limitations
Security-relevant identity, access, invitation, and compliance workflow changes create tenant-scoped audit records.
Evidence available
Database-backed integration tests assert the critical A1 to A3 audit events and their tenant ownership.
Limitation
The audit store is not append-only, hash-chained, WORM-backed, or independently certified. SIEM export and legal hold are planned.
Data processing locations
Service configuration
The service documentation identifies application and primary database hosting in Germany, file storage in London, and restricted administration from Egypt.
Evidence available
The DPA and canonical sub-processor register state the provider, purpose, and processing location.
Limitation
This describes the contracted service configuration. A live infrastructure inventory and residency attestation are separate operational evidence.
Data portability and deletion
Implemented with limitations
Workspace controls, risks, policies, and cross-framework gaps can be exported. Partner deletion uses a 30-day recovery window before scheduled purge.
Evidence available
Scoped export routes, the partner soft-delete boundary, and the retention job exist in the current release candidate.
Limitation
This is not a universal 30-day retention policy for every record type. Financial history requires reconciliation and an approved erasure policy before purge. Backup erasure and a clean disaster-recovery restore still require separate assurance.
Independent assurance
Not yet available
RisQore does not currently claim ISO 27001 certification or a SOC 2 Type II report.
Evidence available
No certificate, auditor report, or independent penetration-test report is represented as available.
Limitation
An independent penetration test and formal certification programme have not been completed.
Legal documentation
Implemented with limitations
A privacy notice, DPA, terms, imprint, sub-processor register, and security contact are published from one versioned source.
Evidence available
The canonical legal module identifies the registered entity, contacts, jurisdictions, service providers, purposes, and processing locations.
Limitation
The current documents are an in-house pre-revenue baseline. They have not yet been reviewed or approved by external legal counsel.
Secrets, resilience, and operations assurance
Not yet available
Enterprise secret vaulting, immutable offsite backups, proven restore objectives, OpenTelemetry, SLOs, SIEM, and formal on-call operations are not claimed as complete.
Evidence available
These controls remain in the separately governed Big4 readiness backlog.
Limitation
Sensitive connector configuration still requires envelope encryption and managed key rotation before this area can pass an enterprise assurance review.
Need to complete vendor due diligence?
Request the current security package, DPA, sub-processor register, or a tenant-isolation walkthrough. We will state what is available and what remains open.