Security, privacy and data governance
Trust should be built on specifics, not slogans.
Security, privacy, data residency, and data governance answer different questions. RiGEL makes those distinctions explicit so Nations can evaluate the platform, its boundaries, and the responsibilities within the relationship.
Security, privacy, data residency, and data governance are different
- 01
Security
Security protects systems and information from unauthorized access, loss, misuse, or disruption.
- 02
Privacy
Privacy governs how personal and sensitive information is collected, used, accessed, shared, and protected.
- 03
Data residency
Data residency describes where data is physically or geographically stored.
- 04
Data governance
Data governance defines who has authority over information, what rules apply, how access is controlled, and how use is managed over time.
Nation control starts with access and authority
RiGEL is designed around the principle that access reflects actual responsibility. Permissions can be scoped by Nation, organization or entity, department, programme, role, individual responsibility, record, field, decision type, and temporary or delegated authority. Being inside the organization does not automatically mean seeing everything.

Nation environments remain separated
A Nation's operational information is not available to another Nation simply because both use RiGEL. Nation-specific environments, permissions, and access boundaries are core to the platform model.

Sensitive information receives narrower access
Sensitive information remains subject to the Nation's authority and information-governance rules. Access is configured around responsibility, not convenience.

- Personal
- Financial
- Health-related
- Family
- Personnel
- Legal
- Governance
- Estate-planning
- Confidential
- Traditional Knowledge
- Culturally restricted
- Other sensitive information
People should be able to access the information they need to perform authorized work - and not more simply because the system contains it.
- Role-based permissions
- Programme-specific permissions
- Record restrictions
- Field restrictions
- Administrative boundaries
- Temporary access
- Delegated access
- Separation of duties
Data residency is important. It is not the same as data sovereignty.

- Hosting
- Residency
- Administrative access
- Contractual protections
- Information governance
Data governance remains a Nation decision
Technology can enforce configured rules.
It cannot decide what a Nation's information-governance rules are.
- Who controls particular records
- Who authorizes access
- What information can leave the Nation
- What can be shared with partners
- What retention rules apply
- How Traditional Knowledge is handled
- What happens when a service relationship ends
- What must be preserved or deleted
Traditional Knowledge requires more than ordinary permissions
Traditional Knowledge, cultural information, community-held knowledge, and restricted materials can be subject to Nation-specific laws, protocols, and restrictions that go beyond ordinary role-based access. Those requirements guide the implementation when this kind of information is involved.
Historical records need controlled integrity
Changes to roles, policies, authority, or configuration do not silently rewrite historical records. Where supported, the record preserves what happened and what changed later.
RiGEL operates within a broader technical environment
RiGEL relies on external infrastructure and service providers for parts of its operation. Those dependencies are part of the system boundary and matter during technical due diligence.
Third-party infrastructure
Integration boundaries
- What data is exchanged
- Which system is authoritative
- How access is authenticated
- What information is necessary
- What happens when the integration fails
- What logs or records remain
- What third-party terms apply
Evidence over adjectives
- military-grade
- bank-level
- unhackable
- 100% secure
- guaranteed data sovereignty
Security and privacy claims need to be grounded in verifiable controls, current architecture, documented practices, and the actual scope of the implementation.
Compliance language needs the same precision.
These are different claims. RiGEL distinguishes between them rather than treating compliance as a blanket label.
Designing controls with a requirement in mind
Supporting a Nation's compliance process
Aligning with a framework
Undergoing an assessment
Holding a certification
Being legally compliant
Responsibility continues across the relationship
Privacy responsibilities are shared and explicit
Those responsibilities are defined through the implementation, agreements, and documented practices rather than blurred together.
The Nation determines
- Many of the reasons information is collected
- Who should access it
- How it should be used
- What Nation-specific rules apply
RiGEL as the technology provider
- Responsibilities defined through the implementation
- Agreements
- Documented practices
Plan for the end of the relationship too
A Nation needs clarity about what happens to its information if its use of RiGEL changes or ends.
- Export
- Format
- Retention
- Deletion
- Backups
- Legal retention obligations
- User access
Bring your technical and governance questions.
A serious evaluation of RiGEL can include the people responsible for privacy, security, IT, governance, legal risk, and information management. We would rather answer difficult questions early than hide them behind a sales process.
