Skip to content

All documents public, all kept current with each release

Vol. I · No. 127RahotoFrankfurt · EU-hosted

“The evidence your security team will ask for.”

Trust Center

The evidence your security team will ask for.

Architecture, threat model, vulnerability response SLAs, sub-processor list. All public, all kept current with each release. Need something not listed?[email protected].

Index of documentsp. 2

What's public, what's NDA, what's not yet

Three honest disclosures.

Why some docs are summaries, not full.

Our architecture and STRIDE threat model exist as full internal documents and are shared under NDA during procurement. We don't publish the full versions here because they'd be reconnaissance for an attacker and competitive copy material — neither helpful to legitimate buyers. The summaries above let your security team assess our maturity at the proposal stage.

What we don't yet claim.

Rahoto does not currently hold paid third-party attestations (SOC 2 Type II, ISO 27001, HIPAA, FedRAMP). We don't put badges on this page for certifications we haven't earned — when one is issued, it appears here with the auditor's report attached.

What you can have today.

Public commitments on SLAs and sub-processors. NDA-gated full architecture, threat model, and pen-test summary on request. Security questionnaires returned in 3–5 business days.

Questions?p. 3

Talk to security or talk to enterprise.

Security team

For vulnerability disclosure, security questionnaires, threat-model questions.

[email protected]

Enterprise team

For DPAs, MSAs, custom procurement, BYOK configuration, residency planning.

[email protected]