Skip to main content

Trust & Policies

Security is a product boundary, not a badge.

RIOS protects each organization at the data layer, limits people and automation to explicit authority, and keeps payment credentials and regulated financial information with the payment provider.

Current controls

What the live platform enforces today.

Organization isolation

Organization records are private by default. Database row-level security enforces tenant boundaries below the application layer, and tests exercise cross-organization refusal paths.

Least-privilege access

Staff capabilities control which workspaces and actions a person may reach. Financial, staff-administration and other sensitive controls remain separate from ordinary training access.

Attributed history

Material state changes are attributed and written to an append-only, tamper-evident audit chain. Corrections preserve prior evidence instead of silently rewriting history.

Hosted payment handling

RIOS Payments uses Stripe-hosted identity, bank, checkout and payout surfaces. RIOS does not store card, bank-account or regulated identity details, and each connected business remains merchant of record for its own customers.

Human authority

Automation may prepare routine work, but it does not independently approve high-impact training, medical, financial, contractual, scheduling, publishing or authorization decisions.

Production boundaries

Secrets stay in managed production configuration. Health admission, signed webhooks, bounded inputs, origin checks, rate limits, provider timeouts and rollback controls protect external paths.

Honest assurance boundary

RIOS builds toward strong operational controls but does not claim SOC 2, ISO 27001, an external penetration test, or another certification unless that review has actually been completed and published.

RIOS Teach remains a development preview and is not authorized for real student records. Future Vision Intelligence, Guardian Angel and Canine Biosystem capabilities are separate releases, not current launch claims.

Report a security or privacy concern

Use the RIOS contact route and select Support. Include the affected page, what you observed and a safe way to reach you. Do not include passwords, payment credentials, private customer records or exploit data in the first message.

Privacy notice

See what RIOS collects, why it is used, which providers support delivery and how to request access or deletion.

Read the privacy notice →

Service terms

Review account responsibilities, acceptable use, subscription boundaries and the relationship between RIOS and connected businesses.

Read the service terms →

Business onboarding

See the exact path from plan selection through workspace setup, payment readiness and launch review.

See onboarding →