EasyRisk.io Trust Center
Trust your risk register — and the controls behind it
EasyRisk.io is designed to keep your risk data protected, isolated and traceable.
We don’t simply assume those protections work — we build them into the product, verify them through continuous testing, and reinforce them in how we operate the service.
This Trust Center explains the measures behind that approach, so you can understand how EasyRisk.io protects your data and evaluate us as a supplier. Where legal terms apply, our Privacy Policy and Terms remain the binding documents.
Hosting and data residency
EasyRisk.io and its database run on infrastructure provided by IONOS SE.
Application data stored by EasyRisk.io, including risk data and backups, remains within the EU/EEA and Switzerland.
Sub-processors
We keep the number of third parties involved in operating EasyRisk.io limited and document what each of them does.
| Processor | Purpose | Location | Basis |
|---|---|---|---|
| IONOS SE | Infrastructure hosting the application and database | Germany | Processor inside the EU |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Subscription payments on paid plans | Ireland, United States | Standard Contractual Clauses, EU–U.S. Data Privacy Framework |
| Resend | All outbound email | United States. Mail is dispatched from Ireland (eu-west-1) | Standard Contractual Clauses |
| Cloudflare, Inc. | DNS and forwarding of email sent to our published addresses | United States | Standard Contractual Clauses. Cloudflare does not proxy EasyRisk.io application traffic. |
| Microsoft Ireland Operations Ltd. | Mailbox receiving correspondence sent to our published addresses | Ireland | Processor inside the EU |
For product analytics, we use Umami on our own servers. Umami runs only on public pages, sets no cookies and stores no personal data. It is never loaded inside the EasyRisk.io application.
Payment data
Payment card details are entered directly into Stripe's systems. EasyRisk.io never receives or stores card numbers.
We retain only the Stripe customer and subscription identifiers together with the applicable EasyRisk.io plan.
A workspace with an active subscription cannot be deleted. This prevents a subscription from continuing after the workspace and its members have lost access to it.
Tenant isolation
Every record in EasyRisk.io belongs to exactly one workspace.
Workspace isolation is enforced using Row-Level Security (RLS) in the database rather than relying solely on application code. The database applies the workspace boundary to every query and rejects access to records belonging to any other workspace.
This provides an additional security boundary even if application logic would behave incorrectly.
We verify that boundary automatically before every release. The check runs in continuous integration, on a separate database that is created for the job and destroyed with it, using test fixtures rather than customer data. It validates isolation all the way down to individual database contents rather than merely checking whether a database row remains hidden.
Access control and authentication
Access is granted per board using three roles: Admin, Editor and Viewer. Workspace administrators can access every board within their workspace.
Authorization comes from the workspace membership record. User profiles contain no separate role field that could be modified to obtain additional permissions.
Two-factor authentication is available.
Audit trail and immutability
EasyRisk.io keeps the history behind your risk decisions.
Every change to a risk or treatment action records:
- who made the change
- when it was made
- the previous value
- the new value
Audit entries cannot be edited or deleted through the application.
Completed risk reviews are recorded separately with their conclusion, the person who performed the review and the time it was completed. A review record is created only when a review is actually completed.
This means the history shown for a risk reflects what happened, who did it and when.
Backup and restore
The EasyRisk.io database is backed up daily, with the most recent thirty backup runs retained.
Each backup is encrypted and produces a checksum for every file, and those checksums are verified to confirm the integrity of the copy.
Encrypted backups are stored on a separate machine.
We also perform regular backup and restore tests on separate hosts using synthetic data.
Availability and monitoring
Every EasyRisk.io service is checked automatically from within our network. If a service stops responding, an alert is raised via direct message to a team member, so that we can investigate.
Service commitments are defined in our terms of service.
Data export and vendor lock-in
We provide a machine-readable export of your complete risk register on request.
You can export an individual risk as a slide deck containing its:
- scores
- treatment
- justification
- owner
- reviews
- complete change history
For organizations that require control of the underlying infrastructure, EasyRisk.io can also run on your own servers.
Certifications and assurance
We believe security reviews work best when requirements are clear on both sides. If an ISO 27001 certification, SOC 2 report, penetration-test report or another specific assurance is mandatory for your organization, contact us before purchasing. We will tell you directly whether we can meet the requirement.
Data processing agreement
A Data Processing Agreement is available on request.
We can also provide a signed list of sub-processors and help your organization complete its supplier or security questionnaire.
Contact us at hello@easyrisk.io.
Vulnerability disclosure
If you believe you have found a security issue in EasyRisk.io, contact us at hello@easyrisk.io or use the contact information published in our security.txt.
We acknowledge every report and investigate it, including reports that ultimately do not result in a confirmed vulnerability.
Still have a question?
Security and privacy requirements differ between organizations. If something your team needs to evaluate is not covered here, contact us at hello@easyrisk.io and we will answer it directly.