Trust Center
The evidence your security team will ask for.
Architecture, threat model, vulnerability response SLAs, sub-processor list. All public, all kept current with each release. Need something not listed?[email protected].
Index of documentsp. 2
Security architecture
System architecture
Public summary of trust boundaries, identity sources, tenant isolation, data residency, and engineering commitments. Full document with internal services, data flows, and key-store layout is shared under NDA.
Security architecture
STRIDE threat model
Public summary of methodology (STRIDE across eight attack surfaces), scope, cadence, and remediation commitments. The full document (surface inventory, gap log, pen-test findings) is shared under NDA.
Process commitments
Vulnerability remediation SLAs
How quickly we acknowledge, mitigate, and fix security issues by severity. P0: 1h acknowledge / 4h mitigate / 24h fix. Quotable in your MSA.
Compliance
Sub-processor list
Every vendor that touches customer data, what they do, and their compliance posture. 30-day notice on additions.
What's public, what's NDA, what's not yet
Three honest disclosures.
Why some docs are summaries, not full.
Our architecture and STRIDE threat model exist as full internal documents and are shared under NDA during procurement. We don't publish the full versions here because they'd be reconnaissance for an attacker and competitive copy material — neither helpful to legitimate buyers. The summaries above let your security team assess our maturity at the proposal stage.
What we don't yet claim.
Rahoto does not currently hold paid third-party attestations (SOC 2 Type II, ISO 27001, HIPAA, FedRAMP). We don't put badges on this page for certifications we haven't earned — when one is issued, it appears here with the auditor's report attached.
What you can have today.
Public commitments on SLAs and sub-processors. NDA-gated full architecture, threat model, and pen-test summary on request. Security questionnaires returned in 3–5 business days.
Questions?p. 3
Talk to security or talk to enterprise.
Security team
For vulnerability disclosure, security questionnaires, threat-model questions.
[email protected] →Enterprise team
For DPAs, MSAs, custom procurement, BYOK configuration, residency planning.
[email protected] →