This page reflects rigana's security posture today and will expand as the product matures. It is provided for information and does not form part of any contract.
Tenant isolation
Each organization's data is kept separate by design. The application enforces isolation so that one organization cannot see or reach another organization's data, and within an organization, people can be limited to their own business units.
Access control and roles
Access is by invitation, and roles govern what each person can see and do. Administrators manage their own users, and leaders work with the information appropriate to their role and authority. Single sign-on (OIDC) is built but has not yet been used with a customer's identity provider, and two-factor sign-in is on our roadmap.
Encryption
Data is transmitted over encrypted connections (TLS) and stored on managed cloud infrastructure that encrypts data at rest. We continue to strengthen our encryption and infrastructure posture as we grow.
Traceable, explainable answers
rigana computes every figure from your own data and links it back to the source. Answers are grounded in your numbers and the context behind them, not invented. When the data cannot support an answer, rigana says so rather than guessing.
AI and your data
rigana uses a third-party AI model to interpret questions, called with your organization's own AI provider key, so the provider and its terms are your choice. The underlying figures are computed from your data, not generated by the model. We do not sell your data, and we do not use one organization's data to answer another organization's questions. We do not offer a local or on-premise AI model today.
Deployment
rigana runs as a hosted service. Private-cloud and on-premise deployment are on our roadmap and are not available today — if your organisation requires your data to stay inside your own environment, please talk to us before you evaluate us, so we can be straight with you about timing.
Auditability
Significant actions in the application, such as sign-ins, imports and changes to stored keys, are written to an append-only activity log that our team can review when investigating an issue. A screen for customers to view this log themselves is on our roadmap.
Sub-processors
We rely on a small set of trusted providers for AI, hosting and databases, and transactional email. A current list is available on request. See our Privacy Policy for how we handle personal data.
Reporting a concern
If you believe you have found a security issue, please contact hello@rigana.ai. We take reports seriously and will respond.