Enterprise-grade security built into every layer of the Remedy platform — because a GRC platform must be held to the highest security standards.
Effective / Last Updated: March 10, 2026|RiskCognition Corporation| Suite 301, 100 Enterprise Drive, Rockaway, NJ 07866 USA
Security is foundational to everything we build at Remedy. As a platform trusted by compliance and risk professionals to manage sensitive enterprise data, we apply rigorous technical and organizational controls across our infrastructure, application, and operations layers.
EncryptionAES-256 at rest · TLS 1.3 in transit
SOC 2 Type IIAudited annually by independent auditors
ISO 27001Certified information security management
Background checks: All Remedy employees undergo background screening.
Security training: Annual security awareness training for all staff.
Least privilege: Employees access only the systems and data required for their role.
Vendor management: All sub-processors are reviewed for security posture before engagement.
Incident response: Documented IR plan with defined roles, escalation paths, and communication procedures.
Compliance Certifications
SOC 2 Type IIISO 27001:2022GDPR CompliantCCPA CompliantHIPAA ReadyFedRAMP Authorized (Roadmap)
Enterprise customers may request our SOC 2 Type II report and ISO 27001 certificate under NDA through our Contact page.
Vulnerability Disclosure
If you discover a security vulnerability in the Remedy platform, please disclose it responsibly. Submit your findings through our Contact page marked "Security Vulnerability Report." We will acknowledge receipt within 48 hours and aim to remediate critical findings within 30 days. We do not pursue legal action against researchers who act in good faith.
Contact
RiskCognition Corporation — Security Team
Suite 301, 100 Enterprise Drive, Rockaway, NJ 07866 USA
Website: www.goremedy.ai
Questions about this policy? Contact our Legal team.