Rutba

Trust centre

The honest version of the security page.

Every vendor’s trust page says encrypted, compliant and audited. This one separates the three, tells you which of them we have actually been through, and gives you the documents rather than a form that promises them.

A concrete and glass structural junction in hard directional light

Compliance

Engineered against, and certified against, are different claims.

One of these columns is mostly empty. Publishing it that way is the point: a company that will tell you what it has not done yet is a company you can believe about what it has.

StandardEngineered againstIndependently certifiedWhere it stands
UK GDPR & EU GDPR Yes Not yetA data processing agreement, a sub-processor list, and a 48-hour breach notification commitment. GDPR has no certificate to hold.
SOC 2 Type II Yes Not yetControls are built to the trust services criteria. No audit has been performed. Targeted as the platform reaches general availability.
ISO/IEC 27001 Yes Not yetThe information security management practices are modelled on it. Not certified, and we will not imply otherwise.
PCI DSS Yes Not yetCard data never reaches our systems — card capture is not built, and when it is, it will go to a certified processor rather than through us.
WCAG 2.2 AA Yes Not yetPartially conformant and honest about it — the accessibility statement lists what we know is wrong.

Certification costs money and time and neither buys a single control. We are spending both on the controls first, and the audits are scheduled behind general availability rather than in front of it. If your procurement process requires a certificate today, tell us early — we would rather say so than waste your evaluation.

Architecture

What a request passes through before it reaches your data.

Five checks, in this order, on every request. The tenant boundary is not a filter applied late — it is asserted at the gateway and re-checked at the data layer, because a filter is something that can be forgotten and a boundary is not.

The five checks a request passes through: TLS encryption, the gateway verifying the token, the organization context being asserted and re-checked, the entitlement check, and finally the isolated tenant data — with every administrative action written to an audit trail.TLS 1.3Encrypted before it leaves the browserGatewayToken signature and expiry verified, not trustedOrganization contextWhich tenant, asserted internally and re-checkedEntitlementsDoes this plan light this app, for this roleYour recordsIsolated at the data layer. AES-256 at restAudit trailevery administrative action, permission change and support access — exportable by you

Controls

The things a questionnaire asks about.

These are the four that come up first, in the words they come up in.

One secure sign-in

Single sign-on with multi-factor authentication across every product. Access follows your organization roles, so revoking someone takes one action, not seven.

Encrypted end to end

TLS 1.3 in transit, AES-256 at rest, and encryption keys rotated on a quarterly schedule.

Built to the standards buyers ask about

Engineered against SOC 2 Type II, GDPR, ISO 27001, and PCI DSS requirements, with formal certification targeted as the platform reaches general availability.

Every action accounted for

Administrative actions, permission changes, and support access are logged to an audit trail you can export.

Data residency

Where your data is, and where it is not.

Processing takes place primarily in the United Kingdom and the European Economic Area. Where a processor sits outside those, the transfer runs on UK adequacy regulations, the International Data Transfer Agreement, or the EU Standard Contractual Clauses with a transfer risk assessment.

The list is short because we run our own mail transfer agent, our own media file server and our own databases rather than renting them — every sub-processor is named, with what it does and where, and the page says plainly what is not settled yet rather than leaving a gap that reads as an answer.

Reliability

We commit to 99.9% monthly availability for generally available services, measured from outside the infrastructure it is measuring, with service credits when we miss it.

Products in early access carry no such commitment and the service level agreement says so. Applying one number to everything you sell, including the half-built parts, publishes a number rather than a promise.

Recovery point objective
15 minutes
Recovery time objective
4 hours
Backup retention
35 days
Breach notification
48 hours

Status

All services operating normally

Incidents affecting a generally available service are posted to the changelog and emailed to the administrative contact on every affected organization.

Being honest about this one: A probe-driven status page with historical uptime is not built yet. A stale status page is worse than none, so this is the small honest version until the monitoring behind a real one exists.

Reporting a vulnerability? security@rutba.io. Research on your own organization, without degrading the service for anyone else, is not a breach of our acceptable use policy and we will not pursue you for it.

On request

The long documents, without a form in front of them.

These exist as artefacts rather than web pages, because each is negotiated, countersigned or specific to what you are buying. Ask and a person answers. There is nothing to fill in first, and nothing is withheld until you do.

  • A completed security questionnaire

    SIG or CAIQ shaped, answered rather than deflected

  • Architecture and data-flow description

    For your security review, at the depth it needs

  • A countersigned DPA

    On our paper or yours, with the SCC annexes completed

  • Penetration test summary

    When one exists. It does not yet, and we will say so

  • Insurance certificates

    Professional indemnity and cyber

  • Business continuity summary

    What happens to your service if something happens to us

Ask for any of these →

Send this page to whoever has to approve it.

Then tell us what their questionnaire asks that this page does not answer, and we will answer it — and add it here.