Skip to main content
← Back to Ritsora AI

Data & Security

Last updated August 12, 2026

This page describes the security practices actually implemented in Ritsora AI. We describe only what we do; we do not claim certifications, audits or regulatory approvals we do not hold.

1. Owner-scoped data access

Financial records are stored with the owner attached to each row, and access rules are enforced in the database itself rather than only in the application. A request that is not the owner of a record does not receive that record.

2. Least-privilege roles

The unauthenticated role has no write access to financial or personal tables. The signed-in role holds only the privileges it needs, and administrative operations are separated from ordinary user operations.

3. Automated security regression testing

Data-ownership rules, role privileges and privileged database functions are covered by an automated regression suite that runs alongside our normal tests. Its purpose is to make a security fix permanent rather than a one-time change.

4. Authentication

Accounts are protected by password or supported sign-in providers, and time-based one-time password (TOTP) two-factor authentication is available in your account settings. Sessions are managed by our authentication provider. Data is transmitted over HTTPS.

5. Payments

Subscription payments are processed by Paddle as Merchant of Record. We do not receive or store full card numbers.

6. Data you control

You choose what to record in Ritsora. You can edit or delete your records, export a report of your information, and request deletion of your account as described in our Privacy Policy.

7. Reporting a vulnerability

If you believe you have found a security issue, please contact us at support@ritsoraai.app with enough detail to reproduce it. Please do not publicly disclose it before we have had a chance to respond.

8. What we do not claim

We do not claim regulatory licensing, financial-services authorisation, or third-party security certification. Where a feature depends on an external integration that is not connected, Ritsora says so rather than implying the data is live.