A risk tool has to be trustworthy itself.
We hold ourselves to the standards we help you enforce on everyone else: enterprise-grade security, privacy by design, and continuous assurance. Here's the detail, no NDA for the basics.
Our security program is aligned to leading frameworks and built on industry best practices.
Explore compliance →Mapped to rigorous global standards
We operate in alignment with these standards today; formal certifications sit on the roadmap, and we'll tell you exactly where each one stands.
Roadmap reflects current plan and is subject to change.
What Dave sees, and what he never does
Dave is our assessment engine: he reads questionnaire responses and proposes grades. If an AI is going to touch your vendor data, you deserve to know exactly how. Here is exactly how.
The questionnaire answers being graded and the evidence attached to them. Nothing else from your workspace, and never another customer's data: every tenant is isolated.
Inference runs on OpenAI's API, disclosed on our sub-processor list, under API terms that exclude customer data from model training.
Neither Altisium nor our AI provider trains models on your data. Your questionnaires improve your assessments, not anyone's model.
Dave proposes a grade with its confidence and the evidence he cited. Your reviewer accepts or overrides it, and every decision keeps a full audit trail.
Questions about the AI pipeline? Ask the security team. Real answers, not a black box.
Assurance, in detail
Questions about security, or need custom assurance?
Our security team responds fast. Enterprise-focused, no runaround.