Trust & Security Center

We're committed to protecting your data and maintaining the highest security standards for vendor risk assessment.

Security Practices

Industry-leading security controls and monitoring

Infrastructure Security

Enterprise-grade cloud infrastructure

Compliance & Privacy

Meeting global data protection standards

Healthcare Industry Clarification

Important Note for Healthcare Organizations:

RRR is a vendor risk assessment platform that analyzes publicly available information about third-party vendors. We do NOT:

Why This Matters:

If You Require a BAA: For organizations with specific compliance requirements that extend beyond our standard service scope, please contact enterprise@rrr.dev to discuss custom arrangements.

Data Scope & Processing

RRR does not process, store, or transmit Protected Health Information (PHI), payment card data (PCI), or other regulated sensitive data categories.

RRR is a vendor risk assessment platform that analyzes publicly available information about third-party vendors. We help organizations evaluate vendor security, privacy, and compliance postures before procurement decisions.

What we process: Vendor URLs, publicly available vendor documentation, your organization's assessment preferences, and user account information. We do not access, process, or store your customers' data, health records, financial transactions, or other sensitive business data.

Incident Response & Breach Notification

We maintain comprehensive incident response procedures:

Vulnerability Disclosure

Safe harbor for security researchers

View Full Security Policy →

Security Resources

Legal & Compliance Documents

Security Contacts

Sub-Processors & Service Providers

Last updated: December 9, 2025

We work with trusted third-party service providers who are bound by strict data protection obligations. We notify customers of material sub-processor changes with at least 30 days advance notice.

Infrastructure

AI & Analysis

Business Operations

For the complete list of sub-processors and their purposes, see our Privacy Policy.