Trust & Security

Security at Rationale IQ

Rationale IQ is built on a defense-in-depth foundation — security controls at the application layer, the backend, and every AI service we integrate with, so financial reporting teams can rely on the platform with the same rigor they apply to their own filings.

Defense in Depth

A Layered Security Foundation

The platform incorporates security controls provided both by the application itself and by the underlying infrastructure used to host and operate the solution. Each layer is designed to work together, so a gap in one is caught by the next.

Application

Authentication, access control, and validation built into every workflow.

Website & Hosting

Encrypted delivery, DDoS mitigation, and versioned deployments.

Backend & Data

Encrypted storage, row-level access policies, and secure sessions.

AI Services

Server-side calls only — credentials never reach the browser.

Security Layer 01

Application Security

The platform includes the following security measures:

Secure authentication — user login is protected with industry-standard authentication practices.

Role-based access control — users can only access features and data permitted by their assigned role.

Protected application routes — unauthorized access to restricted areas of the platform is prevented.

Server-side validation — sensitive operations are validated on the server, not just in the browser.

Encrypted credential handling — API credentials are stored using encrypted environment variables.

HTTPS encryption — all communication between users and the platform is encrypted in transit.

Input validation — reduces the risk of malicious or malformed requests reaching the system.

Security Layer 02

Website Security

The website is hosted on secure, enterprise-grade infrastructure that provides the following security features by default:

HTTPS with automatic SSL/TLS — certificates are provisioned and renewed automatically.

Secure global content delivery — content is served through a hardened, distributed network.

DDoS mitigation — distributed denial-of-service attacks are detected and mitigated automatically.

Immutable, versioned deployments — every release is tracked and can be reverted if needed.

Encrypted environment variables — deployment secrets are encrypted, not stored in plain text.

Secure edge network — helps protect against common web-based attacks.

Security Layer 03

Backend Security

The backend provides infrastructure, authentication, and database services with the following security capabilities:

Secure authentication — passwords are encrypted at rest.

JWT-based authentication — used to secure user sessions.

Row Level Security policies — restrict database access according to user permissions.

Database encryption at rest — protects stored data at the infrastructure level.

TLS encryption — for all data transmitted between the application and the backend.

Role-based database access permissions — limit data access to authorized roles only.

Managed backups and infrastructure monitoring — help ensure data durability and platform reliability.

Secure API access — governed by database security policies.

Security Layer 04

AI Services Security

The platform integrates with its underlying AI services through secure server-side API calls. Security measures include:

TLS encryption — for all communication with AI services.

Server-side API integration — API keys are never exposed to end users.

Encrypted credential storage — API credentials are secured using encrypted environment variables.

Managed secret keys — used for API authentication.

Encrypted connections — all AI requests are processed over encrypted connections.

Security Layer 05

Customer Data Is Not Used to Train AI Models

Customer information remains private and is never used to train or improve AI models. Rationale IQ processes customer data solely to provide the requested analyses while applying privacy-conscious practices throughout the platform.

AI requests are processed solely to generate the requested results — AI interactions are used exclusively to fulfill requested analyses and are not retained for unrelated model training or improvement.

Role-based access controls — Customer information is accessible only to authorized users according to assigned roles and application permissions.

Encryption of data in transit and at rest — Customer data is protected using industry-standard encryption while stored and during transmission between systems.

GDPR-conscious data handling practices — Privacy-conscious processes are applied throughout the platform to support responsible handling of customer information and regulatory best practices.

Secure handling of uploaded files and customer data throughout the application — Uploaded documents and customer information are securely processed, stored, and managed throughout every stage of the application lifecycle.

Our Commitment

Security is not a fixed state at Rationale IQ — it's an ongoing commitment. We continue to invest in and strengthen controls across the platform, the website, and the underlying infrastructure as the product evolves, reflecting our commitment to safeguarding customer data and maintaining the trust of the organizations we serve.

Help Shape the Future of
Accounting & Reporting Intelligence

Interested in learning more about Rationale IQ or participating in our upcoming pilot program? We welcome the opportunity to connect with accounting and financial reporting professionals who are interested in helping shape the future of AI-powered reporting workflows.