Trust & security

The security model we are building RiOS on.

RiOS is in beta. This page sets out the security and privacy model we are building the platform to, alongside how the Revenue Audit already handles your data today. We would rather show the model early than overstate what is live.

Architecture

How data is designed to move through RiOS.

A simple map of the intended flow, from the systems you already use to the numbers on your dashboard. This is the target architecture for the platform, currently in build.

Your existing systems
CRM, ERP, finance, marketing tools
RiOS reading layer
Reads, never replaces
Tokenisation layer
Personal data removed before any AI
AI engine
Row-level security · Fail-closed publication
Leak detection & scoring
One agreed set of numbers
Dashboard & recommendations
What your team acts on
  1. 01Your existing systems

    Everything starts in the systems you already run: your CRM, ERP, finance and marketing tools. RiOS asks for read access only, and you decide which systems it may see.

  2. 02RiOS reading layer

    The reading layer pulls data out of those systems and never writes back on its own; automations only run after you approve them. Your tools stay the source of truth.

  3. 03Tokenisation layer

    Before anything reaches an AI model, a processing step strips names, email addresses and other identifying data and replaces them with tokens. The design rule: a model outside the EU only ever sees tokens, never your customers' real data.

  4. 04AI engine

    The AI engine is built inside two hard rules. Row-level security in the database decides what each user may see, and fail-closed publication means a finding that doesn't clear the confidence bar is never shown.

  5. 05Leak detection & scoring

    Findings from every system are combined into one agreed set of numbers: what leaks, what it costs in euros and how sure we are. No two dashboards that disagree.

  6. 06Dashboard & recommendations

    Only checked results land on the dashboard: the leak, the euro amount and the suggested fix. That is what your team acts on, with the trail back to the source data.

Design rule: data is tokenised before any AI ever sees it.

The platform is built so a processing step removes personal and identifying data before anything reaches an AI model. A model in the US or outside the EU then only ever sees tokens, never your customers' real data. Privacy isn't a checkbox here, it's the default we build to.

Security & compliance

The rules the platform is built to.

Row-level security enforced at the database level

The rule lives in the database itself, not just the app. A broken or misconfigured frontend can't get around it.

Fail-closed AI publication

If the AI isn't sure enough about a finding, it doesn't publish it. Nothing reaches a dashboard unless it clears a confidence bar.

Domain-based access control

Staff access is tied to your verified company domain (checked by DNS), not to hand-managed permission lists.

EU-based data processing

The platform is being built on EU-hosted infrastructure, and we will name every subprocessor before you onboard. Anything sent to an AI model is tokenised first.

Data Processing Agreement before onboarding

A DPA (verwerkersovereenkomst) is part of onboarding: nothing gets connected before it is signed.

Audit answers stay between us

The Revenue Audit itself needs no system access: your answers and our notes are the only data involved, and they are never shared or resold.

Data handling

What RiOS reads, and what it never touches.

Read access to business data, nothing more. This is the exact split.

What RiOS reads
  • Deals, pipelines and account activity from your CRM
  • Invoices and payment status from billing and finance
  • Campaign spend and results from your ad platforms
  • Support tickets and response times
What RiOS never does
  • Send personal data to AI models: it is tokenised first
  • Write or change anything without your approval
  • Reach systems you haven't connected
  • Sell your data, or share it for marketing
Security FAQ

The questions procurement and legal actually ask.

Only your answers to the 120 questions and our own notes. Nothing gets connected to your systems for the audit; there is no integration, no data export, no access to grant.

Within the EU. That is a design requirement for the platform, not an afterthought: we choose EU-hosted infrastructure and will name every subprocessor in the DPA before you onboard. Anything that goes to an AI model is tokenised first.

Yes: signing a DPA (verwerkersovereenkomst) is part of onboarding, before anything is connected. Ask us and we'll walk your legal team through the data flows ahead of that.

The platform is built on two rules: access tied to your verified company domain (checked by DNS), and row-level security in the database deciding what each user may see. No hand-managed permission lists to drift out of date.

Tokens, not people. The pipeline is designed so personal and identifying data is removed before anything reaches an AI model; a model outside the EU only ever sees anonymised tokens.

Your own systems were always the source of truth, so nothing needs to be migrated back. The data RiOS holds is deleted; we keep nothing longer than necessary, in line with our privacy policy.

Methodology

The RiOS Audit follows proven business-analysis methods, including MECE issue trees, the Pyramid Principle and Three Horizons planning, used the same way across 120 questions in 8 areas.

Questions from procurement or legal?

Ask us anything about the data flows, the DPA, or the architecture. You'll talk directly to the person building it.

Ask your question