Rectiva Portico Risk managed. Value created.

Governance

Security and data protection

Rectiva Portico holds the risk registers, incident records and compliance evidence of regulated financial institutions. This page states how that data is protected, and what is not yet in place.

Last reviewed 31 July 2026.

Access control

  • Two-step sign-in is required for every user, at every role. A password alone does not grant access to the platform.
  • Access follows the three lines of defence. Internal audit holds read access it cannot write through; first-line users are scoped to their own business unit.
  • These restrictions are enforced in the database with row-level security policies and triggers, not only in the interface, so they hold even against a request that never goes near our application code.
  • Sensitive actions require a second person. A risk review cannot be approved by the person who submitted it, and neither can a financial crime risk assessment.
  • Periodic access recertification prompts an organisation to reconfirm who still needs access.

Tenant isolation

Each institution's data is isolated at the database level. This is not asserted on trust: an automated test suite runs against a real database and attempts, as a signed-in user of one organisation, to read another organisation's records both by listing and by direct identifier. Those tests are part of the codebase and are run when the isolation rules change.

Encryption and hosting

  • Data in transit is encrypted with TLS.
  • Data at rest is encrypted by the managed database platform.
  • Data is hosted within the European Union (Frankfurt, Germany) by a managed database provider operating under EU data-protection law. For institutions based in Kenya or Uganda, transfers from your jurisdiction to the EU are supported by equivalent safeguards and standard contractual arrangements, providing protections consistent with the Kenya Data Protection Act 2019 and the Uganda Data Protection and Privacy Act 2019. In practice, the nature of data typically held in the platform, namely staff records and internal governance documentation, means data-localisation requirements under CBK or BoU frameworks are unlikely to be triggered. We confirm the applicable position for your specific licence and regulator before contracting.

Audit logging

An append-only audit log records access and configuration change: user invitations, role changes, and actions taken across the risk, policy, compliance and incident modules. Update and delete against the log are blocked by a database trigger.

Our own staff's access to your data

Our staff have no standing ability to read a customer's records. Support access requires a session that is time-boxed, opened with a recorded reason, and attributed to the individual member of staff, never disguised as one of your own users. That access is written into your organisation's audit log, where you can see it, rather than only into an internal record you would have to ask us for.

Data retention and deletion

Retention is configurable per institution to match the requirement of its own regulator. On termination, an institution has 30 days to retrieve its data, after which the data is deleted within 60 days of termination.

What is not yet in place

We publish this deliberately. A governance platform that lists only its strengths is modelling exactly the behaviour it exists to prevent. The following are open items, tracked and prioritised rather than quietly omitted.

  • No third-party penetration test has been carried out. A self-directed hardening review has been run; that is not the same thing, and we do not present it as such.
  • No SOC 2 or ISO 27001 certification. The technical controls those frameworks require are being built ahead of any audit, so that an eventual audit confirms existing practice rather than triggering new work. We are not certified today.
  • No customer-managed encryption keys. If your institution requires them, we cannot meet that requirement at present.

Due diligence

A full vendor due-diligence pack is available to prospective and current customers on request. It is more detailed than this page and includes the same open items, along with the scope limitations behind each control. If you are running third-party due diligence on us, ask for it. The answers you need are already written down.

Request the due-diligence pack →

Reporting a vulnerability

If you believe you have found a security issue, email security@rectivaportico.com. We do not currently operate a paid bug bounty, and we will not take legal action against anyone who reports a genuine issue to us in good faith and gives us reasonable opportunity to fix it before disclosing it publicly.