Effective Date: January 21, 2026
Last Updated: January 21, 2026
At RiskInMind™, we are committed to protecting the confidentiality, integrity, and availability of our clients data, including nonpublic personal information (NPI) handled on behalf of financial institutions such as credit unions. This Security Policy outlines our comprehensive approach to information security, aligning with industry standards and regulatory requirements. It complements our SOC 2® Report (available upon request under NDA for qualified clients) and our Privacy Policy, which details data collection, use, and protection practices.
This policy applies to all RiskInMind.ai services, including our AI-powered agents for loan assessment, regulatory compliance, and document generation. We design our controls to support clients in meeting obligations under the Gramm-Leach-Bliley Act (GLBA), Federal Trade Commission (FTC) Safeguards Rule, and National Credit Union Administration (NCUA) regulations, including Part 748 and Appendices A and B.
RiskInMind™ adheres to key regulatory frameworks to ensure secure handling of sensitive financial data:
For more on data privacy specifics, refer to our Privacy Policy, which includes commitments under CCPA/CPRA, GDPR (for applicable clients), and GLBA privacy rules.
Our security program is risk-based and includes the following safeguards, aligned with NCUA Appendix A (Guidelines for Safeguarding Member Information):
These controls are tested annually via internal audits and external assessments, as detailed in our SOC 2® Report.
We maintain a documented Incident Response Plan (IRP) to address security incidents efficiently, supporting NCUA Appendix B (Guidance on Response Programs for Unauthorized Access to Member Information).
For privacy-related incidents, see our Privacy Policy section on Data Breach Response.
Aligned with our Privacy Policy, we handle data as follows:
For clients like credit unions outsourcing functions (e.g., loan assessment):
We encourage responsible disclosure of vulnerabilities in our web and mobile applications.
Our SOC 2® Type 2 Report, issued by SECURANCE PRO, validates the operating effectiveness of our controls over a 12-month period. Key findings include no material weaknesses in security or privacy criteria. Clients can request a copy under NDA for due diligence purposes. The report aligns with AICPA Trust Services Criteria and supports GLBA compliance demonstrations.
For questions or to request documents, contact hello@riskinmind.ai.
This policy is reviewed annually or upon significant changes. By using our services, you acknowledge this policy