Risk disclosures

The risks we want you to know about

A vendor that says they have no risks has not looked. This is the same register our board sees, lightly redacted for customer detail. Inherent rating is before mitigation; residual is what remains after our controls.

Disclosed risks

8

Reviewed quarterly by board

High residual

0

None at present

Medium residual

3

Mitigations in flight

Low residual

5

Within stated appetite

Material risks

RD-01·Platform concentration

Material dependency on Meta and Google APIs

Inherent · HighResidual · Medium

Description

≈ 71% of pacer decisions touch Meta or Google APIs. A material API regression or policy change on either could degrade pacing accuracy for affected workspaces.

Mitigation

Multi-region API clients · canary releases · 30-day vendor change tracker · published fallback runbooks · monthly partner sync.

Owner: VP EngineeringLast reviewed 2026-03-01
RD-02·Model risk (AI)

Pacer model error in tail regimes

Inherent · MediumResidual · Low

Description

Pacer relies on a forecast model with documented MAPE bands. In black-swan regimes (e.g., sudden inventory collapse) tail error can exceed bands.

Mitigation

Hard guardrails on /policies · pacer never exceeds policy cap regardless of model output · model card on /model-cards · drift monitor on /forecast-accuracy.

Owner: Head of MLLast reviewed 2026-02-19
RD-03·Vendor / supply chain

Compromise of a critical sub-processor

Inherent · MediumResidual · Low

Description

Sub-processors on /legal/subprocessors include cloud and observability vendors whose compromise could affect availability or data integrity.

Mitigation

Annual vendor risk reviews · /vendor-risk live ratings · SLSA L3 build provenance on /supply-chain · contractual breach notification ≤ 24h.

Owner: Security partnerLast reviewed 2026-02-22
RD-04·Regulatory

Cross-border payouts under PSD3 / DORA

Inherent · MediumResidual · Medium

Description

Treasury feature exposes the company to evolving EU payment-services and operational-resilience rules; non-compliance could limit payout corridors.

Mitigation

Regulatory map on /regulatory-map · quarterly counsel review · feature flags allow corridor disablement within 60 seconds.

Owner: General CounselLast reviewed 2026-01-30
RD-05·Operational

Single-region storage failure for ledger

Inherent · MediumResidual · Low

Description

Trust ledger has a primary region; a multi-AZ failure plus a slow regional failover could delay write acknowledgements.

Mitigation

RTO ≤ 15 min / RPO ≤ 60 s on /resilience · quarterly DR drills on /dr-drills · automatic read-only mode that preserves customer visibility during failover.

Owner: Head of SRELast reviewed 2026-02-11
RD-06·Concentration (customer)

Top-5 customer revenue concentration

Inherent · LowResidual · Low

Description

Top five customers represent ≈ 18% of ARR. Concentrated loss could pressure operating cash flow.

Mitigation

Diversification policy on /capital-allocation · multi-year contract weighting · no single customer > 8% individually.

Owner: CFOLast reviewed 2026-02-28
RD-07·Information security

Insider misuse of privileged access

Inherent · MediumResidual · Low

Description

Despite least-privilege, an authenticated insider could attempt cross-tenant action.

Mitigation

JIT access on /access-paths · per-tenant data keys · continuous tenant-isolation tests on /tenant-isolation · 2-of-3 approvals on /payouts.

Owner: CISOLast reviewed 2026-02-25
RD-08·Macro / FX

EUR weakness against USD billing

Inherent · MediumResidual · Medium

Description

Operating costs partially USD-denominated; sustained EUR weakness compresses gross margin.

Mitigation

Rolling 12-month FX hedge on /hedging · annual price-list review on /price-list · natural hedge from USD-billing customers.

Owner: TreasurerLast reviewed 2026-02-05

How we run this register

  • The board reviews this register every quarter; material changes are disclosed within 30 days.
  • New risks are added when an incident, audit finding, or external development crosses materiality.
  • Residual rating drops only after the mitigation has run in production for 90 days without exception.
  • Customers under MSA can request the unredacted register under NDA via /data-room.