Trust Center

Security & Compliance

Ridhics is built for institutional investors. We believe trust is earned through transparency — here is exactly where we stand on security, data handling, and compliance.

Security Controls in Production

These controls are live today — not roadmap items. Every Ridhics deployment includes these from day one.

Authentication & Access Control

  • Google & LinkedIn OAuth 2.0 (PKCE)
  • Enterprise SSO/SAML via WorkOS (available on request)
  • Role-based access control (Owner, Admin, Analyst, Viewer)
  • Session management with immediate revocation
  • JWT tokens with SHA-256 hashed session binding

Multi-Tenancy & Data Isolation

  • Organization-scoped data model — auth, audit, and enterprise data paths tagged with org_id
  • Application-level tenant filtering on protected data endpoints
  • Row-Level Security (RLS) on PostgreSQL audit logs, expanding to additional tables
  • Separate session tokens per user — no shared state across orgs
  • Audit logs isolated per organization

Encryption

  • TLS 1.3 enforced for all traffic (HTTPS only)
  • AWS RDS encryption at rest (AES-256)
  • JWT tokens signed with HS256
  • No sensitive data in URL parameters or browser history

Audit & Monitoring

  • Every API request logged: who, what, when, result, duration
  • Append-only audit logs — UPDATE/DELETE blocked by database-level policy
  • Request ID tracing across services
  • Admin dashboard for audit log review
  • Structured logging with AWS CloudWatch integration

Data Handling & Privacy

How we handle your data, in plain language.

AI Model Providers (subprocessors that process client requests)

EVA uses commercial language models from OpenAI, Anthropic, Google, and Voyage AI to read filings, synthesize research, and generate analytical narrative. All API calls originate from EVA’s backend servers — language models have no direct access to client accounts, databases, or stored documents. Where the provider offers it, EVA is configured for zero-retention API access: prompts and model responses are not retained by the provider beyond the duration of the request and are not used for model training.

Financial Data Sources (data we ingest; no client data flows to them)

EVA’s analytical engine ingests publicly available financial filings, market data, and macroeconomic series from established providers. These are upstream data feeds — client data is not sent to any of them.

User Data

Ridhics stores only what is necessary: account identity (email, OAuth provider), organization membership, session metadata, and platform usage logs. Valuation work and analytical history are stored per-organization. We do not sell client data.

Data Residency

All Ridhics infrastructure runs in AWS US-East-1 (Virginia). The application uses AWS RDS PostgreSQL for storage with daily backups (7-day retention) and point-in-time recovery. No replication outside the United States.

Analytical Integrity

Institutional buyers regularly ask: how do we know an AI-powered research platform isn’t fabricating financial numbers? EVA is architected so this failure mode does not exist in our valuation layer. Financial numbers in EVA reports — fair values, growth rates, margins, terminal values, sensitivities — are computed by deterministic valuation engines, not generated by language models. The role of AI in EVA is to read, structure, and explain — not to invent financial facts. This is structurally different from generative AI tools with hallucination guardrails bolted on: guardrails reduce risk on a generative path; EVA’s architecture removes the generative path from the layer that produces financial numbers.

Every published number traces to a source

Public filings (with accession number, filing date, and underlying concept), established market data feeds, or computed formulas with explicit inputs. There is no “the model just knows this” category in an EVA report.

Methodologies are published and versioned

EVA uses standard institutional valuation frameworks (Damodaran FCFF, McKinsey value drivers, sector-specific models including Residual Income for banks, FFO/NAV for REITs, and credit diagnostics for distressed firms). Same inputs always produce the same output.

EVA abstains when it cannot credibly value a company

A meaningful share of our coverage universe receives an honest “Under Review” with a structured reason rather than a confidently-wrong number. Refusal to publish is a feature, not a gap.

Every valuation is reproducible

EVA snapshots the exact inputs used for every published valuation. Any historical EVA output can be re-computed bit-for-bit on demand.

For institutional diligence, detailed methodology documentation, our analytical-integrity brief, and platform comparison materials are available to qualified prospects on request. Contact ram@ridhics.com.

Compliance Roadmap

Transparent about where we are and where we’re headed.

Q1 2026

Completed
  • Enterprise authentication (OAuth + SSO-ready)
  • RBAC with four-tier role model
  • Audit logging on all API endpoints
  • Multi-tenant data isolation (app + RLS)
  • Session management with revocation
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Formal security policy framework covering information security, access control, data classification, data retention, change management, incident response, vendor management, and acceptable use — details available to qualified prospects on request

Q2 2026

In Progress
  • SOC 2 Type I evidence collection
  • Vendor Risk Questionnaire (VRQ) response bank
  • Penetration testing (third-party)
  • WorkOS SSO integration for enterprise customers

Q3-Q4 2026

Planned
  • SOC 2 Type I audit engagement
  • Formal incident response plan + tabletop exercise
  • Data Processing Agreement (DPA) template
  • Annual security awareness training
  • Automated vulnerability scanning in CI/CD

Infrastructure Architecture

Compute

AWS EC2 behind CloudFront CDN with automatic TLS certificate management. Next.js frontend served as static assets. Python/FastAPI backend with async processing.

Database

AWS RDS PostgreSQL with encryption at rest. Automated daily backups with 7-day retention and point-in-time recovery. Separate schemas for application data, auth, and analytics.

AI/ML Pipeline

LLM APIs (OpenAI, Anthropic, Google) accessed via API keys with zero-retention settings. Voyage AI for embeddings. No user data used for training. All API calls logged and auditable.

Data Pipeline

Public financial filings and structured financial data are ingested from established providers, parsed, and validated against as-filed values. News and market data are sourced from established financial data providers.

Frequently Asked Questions

Does Ridhics use my data to train AI models?

No. We use LLM provider APIs (OpenAI, Anthropic, Google) via API keys with zero-retention settings. Your data is never used for model training.

Can other organizations see my valuations or reports?

No. Every piece of data is tagged with your organization ID. Application-level filtering and PostgreSQL Row-Level Security ensure complete isolation.

Do you support SSO/SAML for enterprise login?

Yes. We integrate with WorkOS for enterprise SSO/SAML. Contact us to set up your identity provider connection.

Where is my data stored?

All data resides in AWS US-East-1 (Virginia) on encrypted RDS PostgreSQL instances. Application servers run on EC2 behind CloudFront CDN.

Are you SOC 2 certified?

Not yet. We are actively building toward SOC 2 Type I with a target audit engagement in Q3-Q4 2026. Our current security controls are designed to meet SOC 2 requirements.

Can I get a Vendor Risk Questionnaire (VRQ) completed?

Yes. Contact ram@ridhics.com with your VRQ or security questionnaire and we will complete it within 5 business days.

Need More Detail?

Ridhics maintains a detailed materials pack for institutional prospects in active diligence. Items available on request to qualified prospects include:

  • • Full methodology and analytical-integrity documentation
  • • Security policy documents (8 areas covering the formal framework)
  • • Vendor Risk Questionnaire pre-filled response bank
  • • LLM data handling specification
  • • SOC 2 Type I readiness roadmap (target: Q3–Q4 2026)
  • • Sample reports and platform demo access

VRQ submissions: 5 business-day response SLA. Security review or methodology deep-dive requests: 1 business-day SLA to schedule.

Send VRQRequest Security Review