Security at Rilk

Your inventory, orders, and customer data run your business. Protecting them isn't a premium tier or a roadmap item — it's how the platform is built.

Encryption in transit and at rest

Every connection between your browser and Rilk is encrypted with TLS 1.2 or higher. All stored data is encrypted at rest with AES-256, and the most sensitive items — like the connection credentials for your marketplaces and shipping carriers — carry an additional layer of application-level encryption on top.

Multi-factor authentication on every account

Multi-factor authentication is enforced for all Rilk accounts — yours, your team's, and our own staff's. A password alone is never enough to reach your data.

Role-based access

Access inside Rilk follows least privilege. Granular roles and permissions control exactly what each member of your team can see and do, and every account's data is strictly isolated from every other account's.

Continuous vulnerability scanning

Automated security scanning runs on a fixed cadence: code and dependency analysis weekly and cloud-configuration reviews monthly, alongside continuous automated security monitoring of our production cloud environment. Findings are triaged, tracked, and remediated on defined timelines.

Independent infrastructure attestations

Rilk runs on enterprise-grade cloud infrastructure from Amazon Web Services, which maintains its own independent third-party attestations — including SOC 1, SOC 2, SOC 3, and ISO 27001 — covering the physical, environmental, and foundational security of the platform Rilk builds on. Rilk reviews those reports as part of its own vendor-management program.

SOC 2 Type II — in preparation

Rilk is preparing for a SOC 2 Type II examination. Our controls have been operating under a formal observation window since July 2026, with evidence collected and signed off on a fixed cadence. We have not yet engaged an audit firm and no SOC 2 report has been issued; we will publish one when it is. Separately, an independent third-party penetration test of the Rilk application and API was completed in July 2026, with the vendor report issued in August 2026 after re-validating our fixes — available to prospective customers under NDA.

Responsible disclosure

Found a vulnerability? Email support@rilk.ai with the details and we'll respond promptly — we're grateful to researchers who report issues responsibly and we won't pursue good-faith research.

See it for yourself

Free tier, no credit card required.