Who can see what
Checked against the app on September 27, 2026Three groups of people can see something of your company on Ressura: the members you invite, a lender or investor you choose to share with, and the people who run Ressura. This page says what each can see, and what none of them can.
Your members, by role
Everything in a company belongs to that company and to the people invited into it. There are three roles. The Owner is one person, who alone can transfer ownership, delete the company and give the Owner's approval to rejecting a fraud-risk finding. An admin connects and disconnects Connections, manages members, subscribes to modules, buys top-ups and sees the names of people who appear as subjects. A member adds documents, reads findings and answers Ressura's questions, and sees an id rather than a name where a subject is a person. Members and roles has the full list.
Nobody outside the company sees anything unless someone in it chooses to share. Removing a member removes their access at once.
A lender or investor you share with
A fund that uses Ressura can ask your company to take part in an engagement: a named review against chosen modules. Taking part needs a verified account under the invited email address, so a forwarded link grants nothing. Within an engagement, each side sees only what is shared for it. The documents that were asked for are visible to both sides; findings are shared deliberately, never by default; and nothing outside the engagement is visible to the other side. A closed engagement is read-only for everyone who took part.
Ressura's own staff
The people who run Ressura reach production systems and customer data only when their work needs it, under least privilege. That access needs strong authentication with a second factor, and it is logged and reviewed. Each person has an individually named account, so an access can be traced to a person. Nobody at Ressura reads your documents to train a model or for any purpose outside running the Service, and the Data Processing Agreement binds Ressura to act only on your instructions.
Providers
A short list of providers runs the Service: hosting, the database and sign-in, payments, analytics and model calls. Each is bound by contract to confidentiality and to using your data only to provide its service to Ressura. None may train a model on it. The Subprocessors page is the list counsel keeps of each provider under contract, what it does and where it is. The outside systems you connect yourself, such as Xero, Google Drive or DocuSign, are your own providers and not Ressura's.
The record of who did what
The activity ledger is the record of the changes that matter, with who made each one and when: an edit to Organisational context, a change to a Control, a disposition, a disconnect, a deletion, a role change. It only grows. Open Activity in Settings to read it.
Read next
Retention and deletion says how long each kind of data is kept and how a company is deleted. The Security Statement lists the controls in force.