👍 Good to know: Riot is a SaaS service. Security follows a shared responsibility model: the cloud provider secures the physical infrastructure, Riot secures the platform and the application, and you keep control of your tenant, meaning your users, their access and the data you import. The full matrix is published on our Trust Center.
1️⃣ Shared responsibility
👉 What Riot takes care of
Hosting in the European Union, on an architecture designed for high availability.
Network: WAF filtering and TLS 1.2 minimum encryption for all traffic with the platform.
Data: encryption at rest (AES-256) and logical isolation of each tenant; no customer's data can be accessed by another customer.
Application: secure development, code review, vulnerability management, hardening of the runtime and dependencies.
Identity and access: application authentication and authorisation, SSO and SCIM, RBAC model.
Monitoring: SIEM, alerting and application logs monitored by Riot's security team.
Backups on a schedule, with regular restore tests.
Incident response on the platform side, and breach notification in line with the DPA.
👉 What you are responsible for
Provisioning and deprovisioning your users promptly.
Enforcing MFA through your identity provider.
Classifying your data before importing it into the platform.
Monitoring usage of your tenant.
Keeping your devices and browsers up to date (patched).
Reporting any suspected security incident to [email protected] without undue delay.
👍 Good to know: Riot is ISO/IEC 27001:2022 certified, with the ISO/IEC 27017 and ISO/IEC 27018 extensions, and holds a SOC 2 Type II report. The certificates are available on the Trust Center. The SOC 2 report and the penetration test report are shared on request, under NDA.
2️⃣ Configuring your workspace securely
👉 Step 1: Connect Riot to your identity provider
This is the recommended setup. Your employees and admins sign in through SSO with their company account, and your authentication policies (MFA, conditional access, session rules) apply to Riot just as they do to your other tools. See Does Riot support multi-factor authentication (MFA)?
👉 Step 2: Sync your employees from your directory
Syncing keeps your user list up to date automatically: when someone leaves your directory, the change is reflected in Riot with no manual action. See Sync my employees and, for Microsoft Entra, How to use the Microsoft Entra SCIM Provisioning Service.
💡 Prerequisite: on Google Workspace, you can run the sync with an account that has restricted directory access, rather than with a super admin account. See Create a Google Workspace account with restricted directory access.
👉 Step 3: Validate your domains
Validation proves that the email domains declared in Riot belong to you, through a DNS record or an IP address allowlist. See Validate a domain.
👉 Step 4: Only enable magic link on the admin platform if you need it
Magic link sign-in is disabled by default on the admin platform. If all your admins sign in through SSO, leave it disabled: access to the admin platform then remains subject to your identity provider's policies.
👉 Step 5: Grant the minimum rights needed
Apply the principle of least privilege: give each admin the most restrictive role that still lets them do their job. Roles and the combinations to watch are detailed in section 4️⃣.
👉 Step 6: Receive integration alerts immediately
Riot notifies admins when an integration (sync, Sonar, compliance) runs into a problem. In your profile, Notifications tab, choose immediate delivery for this type of event rather than the monthly summary.
👉 Step 7: Limit the scope of your API keys
If you use the API, prefer an API key at workspace level rather than at organisation level when your tool only needs data from a single workspace. See How to use the Riot API ?
3️⃣ Authentication mechanisms
👉 SSO
Riot supports SSO through Google, Microsoft, Slack and Okta, as well as OIDC configurations for Entra, Okta, OneLogin and JumpCloud. Authentication is then handled entirely by your identity provider.
👉 Magic link
Passwordless sign-in: the user receives by email a single-use link and a 6-digit code shown only to the person who made the request. The link expires after 15 minutes and only works with the profile's primary email address. It is always available on the employee portal; on the admin platform, it depends on the workspace setting (see section 2️⃣).
👉 API
Every request must include an API key in the x-api-key header. An API key is tied to a single organisation and limited to specific scopes (for example awareness:read or simulation:read).
⚠️ Important: Riot does not provide MFA of its own on its sign-in form. To enforce it, connect Riot to your identity provider: it remains the source of truth for your access policies. An API key is a secret: never share it publicly and, if you think it has been exposed, contact us to revoke it.
4️⃣ Roles and rights
👉 At workspace level
Admin or Read-only, with rights that can be adjusted module by module. See Manage my Admins.
The super admin, shown with a crown 👑, is the account owner. They cannot be removed directly: a transfer of ownership is requested from support.
The developer role, granted by the super admin, lets a person create and manage API keys.
👉 At organisation level
A global admin has access to everything. For each functional area (Users, Awareness, Breaches, Inbox, Settings, Simulation, Sonar), there is an admin role (read and write) and a viewer role (read-only). These roles are granted for the whole organisation or workspace by workspace. See Understanding organization management.
👉 High-risk combinations
Some roles, alone or combined, grant broad access. Keep them to a small number of people and review them regularly:
Global admin: full access to every workspace in the organisation.
Invitation at organisation level: it grants access to every workspace, including those created later.
Developer role combined with an organisation-level API key: programmatic access to the data of every workspace.
Super admin: this is the person who grants the developer role; treat this account like a privileged account in your directory.
👉 Separating duties
Assign Simulation and Inbox to different people when awareness and security operations are handled by two teams: the split by functional area makes this possible.
Give the viewer or Read-only role to people who review results without changing anything (management, auditors).
Only grant the developer role to people who actually integrate the API.
Review the member list in Settings > Members; at organisation level, you can export it as a CSV.
5️⃣ Functions reserved for specific admins
Function | Who | Where |
Invite or deactivate an admin, change their rights | Admin | Settings > Members |
Grant the developer role | Super admin 👑 | Settings > Members |
Create and manage API keys | Developer role | Settings > API |
Transfer account ownership | On request to Riot support | Chat, email |
Enable magic link on the admin platform | Admin with a write role on "User Management" and "Settings" | Settings > Members |
Manage integrations (sync, Albert) and domains | Admin with a write role on "User Management" and "Settings" | Settings > Members |
Create a workspace, invite users in bulk | Organisation admin | Organisation |
👉 When an admin leaves the company
Remove them in two places: in Settings > Members (See details > Deactivate), then in the Team tab, where they also appear as an employee. If they are the super admin, first request a transfer of ownership from support.
6️⃣ Vulnerabilities and updates
👉 Platform updates
The Riot platform is updated by our teams: you have nothing to install to benefit from patches. If an intervention requires service downtime, you are informed on status.tryriot.com.
👉 Components installed in your environment
Some components are installed on your side: the reporting button in Outlook, the Sonar browser extension, and Albert on Slack, Microsoft Teams or Google Chat. When a change requires action on your part, a dedicated article explains it, such as Update Albert on Teams: From Graph API to Setup Policies.
👉 How Riot handles vulnerabilities
Vulnerabilities are identified through automated scans, penetration tests, our Vulnerability Disclosure Program and monitoring of published security advisories. Each one is classified by severity (critical, high, medium, low) and fixed in order of priority according to that level.
👉 How you are informed
For service downtime: status.tryriot.com.
For an incident affecting several customers or a major feature: email, a banner in the platform, or your account manager if you have one.
For an incident that may affect your data or your service: notification as soon as possible through the contractually agreed channel, regular updates until resolution, then an incident report.
In the event of a personal data breach, Riot meets its notification obligations under the GDPR and the DPA.
⚠️ Important: to report a vulnerability, email [email protected] or use our Vulnerability Disclosure Program, whose terms are set out in the security.txt file. We acknowledge every report within 3 working days and give you a resolution timeline.
7️⃣ Error handling and logs
👉 Sign-in error messages
Every failed magic link sign-in displays an explicit message (account not found, link expired or already used, option disabled on the workspace, link opened on another device). What each one means and what to do are detailed in Signing in to Riot with a magic link.
👉 Integration alerts
When an integration fails, admins receive an "integration issue detected" email, sent by Riot from [email protected]. The email is triggered by the incident, once per detected problem. See Why am I receiving an "integration issue detected" email, and how often?
👉 API errors
Rate limits apply per API key; when they are exceeded, the API returns a 429 code until the next time window. The full list of responses and schemas is available on docs.tryriot.com.
👉 Processing history in Inbox
Each Inbox ticket keeps the full processing history of the reported email. See Understanding Inbox.
👉 Your identity provider's logs
With SSO, every sign-in to Riot goes through your identity provider and therefore appears in its own logs, alongside your other applications.
👉 Your workspace audit logs
You can request your workspace audit logs at any time by emailing [email protected], stating the time period and the format you need.
8️⃣ Getting help
Riot support can be reached through the chat built into the platform and by email at [email protected]. For any security matter, email [email protected]. Our security posture is detailed on the Trust Center.
Key takeaways
Security is shared: Riot secures the platform, you manage your users, their access and your data.
Connect Riot to your identity provider: your MFA policy then applies to Riot.
Leave magic link disabled on the admin platform if you do not need it.
Apply least privilege and watch the high-risk combinations: global admin, invitation at organisation level, developer role with an organisation API key.
Receive integration alerts immediately and deprovision admins who leave the company without delay.
Report any vulnerability to [email protected].
Version history
This guide is updated with every significant change to the platform and reviewed at least once a year.
