RAAL Logo
Trust · Security

Built to pass your security review.

Your compliance team will ask about your device vendor. Good. Here are the answers, documented, current, and ready to submit. We can clear your review in days rather than months.

Regulated customers

Your regulators ask about your suppliers. We make that easy.

NIS2, DORA, and gaming licence conditions all push supply-chain obligations down to your vendors. A company that ships, collects, and retires your devices sits clearly inside that scope.

Raal has completed enterprise due diligence for regulated customers. The questionnaires are answered, the policies are written, and the evidence is ready before you ask.

SUPPLY-CHAIN OBLIGATIONS
NIS2 Supply-chain security duties for essential and important entities
DORA ICT third-party risk management for financial entities
GAMING LICENCES Supplier controls under MGA and other licensing regimes
Security program

What is in place today

Current state, not roadmap. Every item below is documented and included in the pack.

01

Documented security policies

A 15-policy set covering information security, access, incidents, vendors, HR, and development. You get the policies themselves, not summaries.

02

Incident response

A 24 hour customer notification target for incidents affecting your data, built to support your own 72 hour regulatory deadlines.

03

Sub-processor vetting

Every sub-processor is vetted before onboarding. You get advance notice of changes and a 10 working day objection window.

04

Access control and training

Role-based, least-privilege access protected with MFA, plus annual security training for everyone who touches the systems.

05

EU data residency

Estonian company, data hosted in the EEA, deletion on a published schedule. How we handle your data

Device retirement

Devices leave your fleet. Data should not leave with them.

Certified data wiping

Retired devices are wiped or destroyed, with data destruction certificates issued for your audit files.

Direct and vetted partners

Wiping and destruction are handled directly by Raal and through vetted partners, under the same contractual controls.

End-of-lifecycle tracking

Every retirement is tracked from collection to destruction, so your audit trail has no gaps at the end of a device's life.

Retirement is the last entry in a record that starts the day a device is issued. That record lives in asset management, which is where an auditor goes for ISO 27001 control 7.14 evidence.

Certifications

Where we stand on certifications, honestly

Raal is not SOC 2 or ISO 27001 certified today. Our security program is aligned to the principles of both, and we will show you exactly where we stand rather than hide behind a badge.

You get direct answers from the people who run the systems, complete questionnaire responses in days, and the policies themselves, not a certificate summary and a six-week queue.

If your framework strictly requires a certified vendor, tell us, we would rather know early.

The due diligence pack

One request. Everything your review needs.

Sent within one business day, in a format you can forward straight to your compliance team.

Completed questionnaire answers GDPR, data flows, sub-processors, incident response, HR security, software development, and cyber risk.
Policy register The full 15-policy set, as maintained, not as summarized.
DPA and sub-processor list The data processing agreement and the current sub-processor register.
30-minute founder call Open questions answered directly by the people who run the systems.

Most vendors treat your security review as friction. We treat it as the sales process.

Start your review with the answers in hand.

One document, one business day, no queue.