Skip to content

Governance

Information Security

An overview of how we protect the confidentiality, integrity, and availability of the information our customers trust us with.

Last reviewed: July 2026

When customers use Risely, they trust us with privileged and sensitive information. Protecting that information is fundamental to how we operate. This page gives an overview of our information security program and the principles that guide it.

Our commitment

We are committed to protecting the confidentiality, integrity, and availability of the information assets in our care, and to responding to and recovering from information security incidents when they arise. We maintain a holistic, risk-based information security program that governs how information is created, stored, shared, and transmitted securely.

We consider our internal and external environment along with the requirements of our customers and other stakeholders, and we determine the risks and opportunities that could affect the products and services we provide. Our leadership provides the resources needed to support the program and its continuous improvement.

What information security means to us

We safeguard three objectives:

  • Confidentiality: data and information assets are confined to people authorized to access them and are not disclosed to others.
  • Integrity: data is kept intact, complete, and accurate, and information systems remain operational.
  • Availability: information and systems are at the disposal of authorized users when needed.

Our objectives

Our information security program is designed to:

  • align security management with our business strategy;
  • protect the information that is important to Risely and its customers;
  • reduce risk related to the use of technology and technology outsourcing;
  • ensure our information assets are accounted for and protected from damage, alteration, loss, and unauthorized use or access;
  • ensure information and systems are available only to authorized users;
  • give customers the means to support their data subjects’ rights to access, correct, or erase personal data, as defined by contract;
  • process personal data only in line with our customer’s instructions;
  • meet the security-related regulatory and statutory requirements that apply to how information is collected, stored, processed, transmitted, and disclosed;
  • dedicate resources to establishing, operating, monitoring, and maintaining security safeguards;
  • build security awareness so that everyone understands their responsibilities;
  • maintain security best-practice guidance and follow it; and
  • review our objectives periodically and continuously improve.

Segregation of duties

We segregate conflicting duties and areas of responsibility to reduce the risk of accidental or deliberate misuse of our assets. Access to, modification of, or use of assets requires proper authorization, and we consider the possibility of collusion when designing controls.

Areas we cover

Our program spans the areas that keep information and services secure across their lifecycle, including:

  • human resources security;
  • access control;
  • asset management;
  • operations security;
  • acceptable use of assets;
  • legal and regulatory compliance;
  • secure system acquisition and development;
  • physical and environmental security;
  • business continuity;
  • vendor and subprocessor management; and
  • incident management.

Security in project management

We integrate information security into how we run projects, so that security risks are identified and addressed as part of the work, whatever the project’s nature.

Working with authorities and specialists

Where appropriate, we maintain contact with relevant authorities and emergency and service providers so that help is accessible during a crisis, and we seek specialist security advice when it is needed.

Reporting security incidents

If someone becomes aware of an information security incident, we expect it to be reported promptly so that we can respond. If you believe you have identified a security issue affecting Risely, please contact us at [email protected].

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]