Security & trust
How Rima protects your clients’ financial data.
Every document your firm handles is someone’s finances at their most exposed. Here is exactly how we treat that responsibility.
Model training
We have zero-retention agreements with every AI provider we use — OpenAI, Anthropic, and others. Your clients' documents are processed to complete a task, then discarded. They are never stored to improve AI models, ours or anyone else’s. We verify these agreements contractually and review them on each renewal.
Encryption
All data is encrypted at rest using AES-256. All data in transit is protected by TLS 1.3. There is no point in the Rima pipeline where client financial data moves unencrypted.
Access control
Access within Rima is role-based. Only authorized users at your firm can see your clients’ information. Case managers see only the cases assigned to them. Firm administrators control who has access to what. No Rima employee accesses client data except where necessary to resolve a support issue you’ve opened.
Data retention
Your firm controls how long client files stay in Rima. We provide documented retention policies and procedures, and we enforce the policy your firm sets. When a file should be deleted, it is deleted.
Independent assessment
Rima is CASA (Cloud Application Security Assessment) certified. We conduct continuous penetration testing. SOC 2 controls are implemented across the full framework — the certification audit is underway. We will update this page and notify customers the day the SOC 2 Type I report is issued.
Reporting a concern
If you believe you’ve found a security issue, contact us directly at security@getrima.ai. We respond to all security reports within one business day and will keep you informed as we investigate.
Questions our overview doesn’t answer? Ask them on a demo →