Defence in depth
Multi-layered network protection with AWS WAF rate limiting, CloudFront enforcing TLS 1.2 and above, and continuous threat detection through GuardDuty.
Security & Llama Vault
Llama Vault brings platform security, encryption, access controls, monitoring and supported data residency options into one reviewable architecture for security teams and vendor assessors.

Enterprise-Grade Protection
The platform uses layered AWS controls for network protection, encryption, identity, recovery and monitoring. Security teams can review the relevant configuration and documentation during assessment.
Multi-layered network protection with AWS WAF rate limiting, CloudFront enforcing TLS 1.2 and above, and continuous threat detection through GuardDuty.
End-to-end encryption using AWS KMS-managed keys across all databases, with credentials stored securely in Secrets Manager.
Strong password policy, optional MFA, custom API authorisers, and admin-controlled user provisioning.
Multi-region replication across EU, US, and Asia-Pacific, point-in-time recovery, automated backups, and deletion protection on all critical resources.
CloudTrail audit logging across all regions, Lambda isolated in VPCs following least-privilege principles, and Sentry monitoring across 15-plus AWS regions.
Llama Vault
Customer data remains within the tenant boundary and is not used to train the model. Supported residency options keep processing and storage in the selected region.
Tenant-specific storage and access controls keep your organisation’s data separated from other customer accounts.
Select a supported region for processing and storage according to your organisation’s data residency requirements.
Risk Llama
Bring your security questionnaire to a product review and examine the controls, architecture and documentation relevant to your assessment.
Have a security questionnaire to complete? Book a live demo and we will walk your team through it.
For security documentation, contact our team at support@riskllama.com.