Skip to content

Security Controls

Access Control

The controls we use to ensure only authorized users can access Risely systems and data, at the appropriate level.

Last reviewed: July 2026

Access to Risely systems and data is granted in a controlled way, based on business need and information security requirements. This page describes the controls we use so that only authorized users can access information assets, at the appropriate level.

Our approach

The principle of least privilege guides our access controls. These controls apply to information and information processing systems at the application and operating system layers, including networks and network services. We assure the confidentiality, integrity, and availability of information by ensuring that only authorized users have access to specific information assets, as needed for their business activities.

We identify and maintain a documented list of critical systems that host services or sensitive data.

Access provisioning

We provide access privileges based on the following principles:

  • Need to know: users or resources are granted access only to the systems necessary to fulfill their roles and responsibilities.
  • Least privilege: users or resources are given the minimum privileges necessary to fulfill their roles and responsibilities.
  • Separation of duties: responsibility for critical actions is distributed among different individuals, so that no single individual can subvert a process.

We apply these using one or both of the following methods:

  • Role-based access control: access to systems and resources is restricted based on defined business functions (for example, executive level or engineer level) rather than the identities of individual users. The roles that may access each critical system are identified and documented, and the ability to grant access is restricted to the administrators of each system. Access required outside the defined role matrix must be documented with a business justification.
  • Rule-based (ticket-based) access control: requests for user accounts and access privileges are formally documented and appropriately approved. Access is requested with details of the specific access needed, and authorization information is retained for the period required by business, contractual, and legal requirements.

Before being granted access to systems that contain customer data, an employee must accept our Acceptable Usage Policy, which outlines responsibilities and commitments regarding the acceptable use of Risely’s assets. When access beyond the default for a role or team is granted, it is limited to the minimum level required for the intended business operation.

Privileged access

Risely operates its access management under the principle of least privilege. A team member is granted only the minimum access necessary to perform their function. Access is considered necessary only when a function or action cannot be performed without it. Least privilege protects Risely and its customers from unauthorized access and configuration changes, and it limits exposure if an account is compromised.

Authentication and secret management

We minimize the use of passwords wherever possible:

  • We use a single sign-on (SSO) mechanism to authenticate wherever possible, ensuring the SSO authentication mechanism is secure.
  • We use multi-factor authentication (MFA) wherever possible, which adds a barrier even if a password is compromised.

Where passwords are the only way to log in to a system:

  • Complex passwords are used wherever possible for accounts that have access to critical data, ideally strong, unique passwords generated by a password manager. Two-factor authentication (2FA) is enforced on all company Google accounts.
  • We strongly advise against reusing passwords that are or were used elsewhere, such as personal accounts, since attackers commonly obtain corporate access using personal passwords exposed in breaches of other services.
  • Any password or authentication details stored within systems owned and managed by Risely are encrypted or masked to avoid exposing them.

Review of access rights

We periodically reconcile user accounts and their associated rights. Reconciliation is performed quarterly for production systems and at least annually for all other systems, and it includes a review of the privileges assigned to users. Where irregularities are found, we take immediate action to remove, disable, or modify the affected access.

Removal or adjustment of access rights

Employment termination or a change of role triggers the relevant processes for revoking or amending access rights. On a role change, access is adjusted so that a user does not retain more rights than required for the new job function. The removal or modification of access rights for departing employees or contract staff is carried out by the relevant administrators.

Secure log-on

For access to critical systems:

  • If a login is unsuccessful, the error message does not reveal which part of the login information was incorrect.
  • The number of unsuccessful log-on attempts is limited.
  • Passwords are not displayed while being entered.
  • Multi-factor authentication is adopted wherever possible, and single sign-on (SSO) is recommended wherever possible.

Inactive sessions are shut down where feasible after a defined period of inactivity, and re-authentication may be required at timed intervals. Session time-out requirements are implemented for all critical systems as feasible and applicable.

Access monitoring

For all production infrastructure, logging is enabled so that user accountability is maintained if issues arise. We also recommend additional security measures, such as intrusion detection and prevention systems, to detect unauthorized access.

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]