HOME / SECURITY & COMPLIANCE POLICY
Trust & Assurance

Security & Compliance Policy

RYHA’s implemented engineering controls, customer responsibilities, evidence boundaries, and current independent-assurance status.

Last Updated: 2026-07-16Version v2.0

This policy is a draft that requires review and approval by qualified legal counsel before public launch. It is provided for general information only and does not constitute legal advice. RYHA Technologies may update it from time to time, and only a formally approved published version should be treated as binding.

Security Governance and Shared Responsibility

RYHA uses risk-based engineering and operational controls intended to protect confidentiality, integrity, and availability. The final program must identify accountable owners, risk review, access approval and review, secure development, change control, asset and data inventories, provider oversight, vulnerability management, incident response, continuity, and policy review. Customers remain responsible for authorized users, credential hygiene, project permissions, lawful content, configured integrations, review of generated work, and security of systems outside RYHA’s control.

Access, Data Protection, and Service Isolation

The repository implements authenticated access boundaries, tenant-scoped authorization, audit paths, redaction helpers, and encryption for protected credentials. Customer data paths are designed for tenant isolation and deny cross-tenant access in covered authorization tests. Encryption in transit, storage encryption, key custody, backup protection, retention, and operator access depend on deployed configuration and must be verified for each production environment. These are implementation statements, not a certification, a perfect-security promise, or a guarantee that every deployment and third-party integration is vulnerability-free. Production access reviews, monitoring, recovery drills, dependency testing, vulnerability scanning, penetration testing, and retained evidence remain launch gates.

Compliance and Independent Assurance

The privacy and engineering program is being prepared around applicable data-protection requirements, including GDPR rights and processor obligations where they apply. RYHA is not claiming full legal compliance, SOC 2 certification, HIPAA compliance, payment-card certification, WCAG conformance, or another independent assurance unless a current scoped report, attestation, approved statement, or executed agreement explicitly supports the claim. Regulated use cases require legal, security, provider, data-residency, and deployment review before acceptance.

Vulnerability Disclosure, Incidents, and Evidence

Potential vulnerabilities should be reported through the Security Policy at security@ryha.dev. Do not test production systems, access data, degrade service, or disclose unresolved findings without written authorization. The repository includes an incident-response process and notification decision tree; actual notifications follow applicable law, role-specific awareness timing, contracts, incident facts, and legal guidance. Customers may request available approved assurance material through the agreed review process, subject to confidentiality, scope, and security limits.

Related policies