Trust centre
The honest version of the security page.
Every vendor’s trust page says encrypted, compliant and audited. This one separates the three, tells you which of them we have actually been through, and gives you the documents rather than a form that promises them.

Compliance
Engineered against, and certified against, are different claims.
One of these columns is mostly empty. Publishing it that way is the point: a company that will tell you what it has not done yet is a company you can believe about what it has.
| Standard | Engineered against | Independently certified | Where it stands |
|---|---|---|---|
| UK GDPR & EU GDPR | Yes | Not yet | A data processing agreement, a sub-processor list, and a 48-hour breach notification commitment. GDPR has no certificate to hold. |
| SOC 2 Type II | Yes | Not yet | Controls are built to the trust services criteria. No audit has been performed. Targeted as the platform reaches general availability. |
| ISO/IEC 27001 | Yes | Not yet | The information security management practices are modelled on it. Not certified, and we will not imply otherwise. |
| PCI DSS | Yes | Not yet | Card data never reaches our systems — card capture is not built, and when it is, it will go to a certified processor rather than through us. |
| WCAG 2.2 AA | Yes | Not yet | Partially conformant and honest about it — the accessibility statement lists what we know is wrong. |
Certification costs money and time and neither buys a single control. We are spending both on the controls first, and the audits are scheduled behind general availability rather than in front of it. If your procurement process requires a certificate today, tell us early — we would rather say so than waste your evaluation.
Architecture
What a request passes through before it reaches your data.
Five checks, in this order, on every request. The tenant boundary is not a filter applied late — it is asserted at the gateway and re-checked at the data layer, because a filter is something that can be forgotten and a boundary is not.
Controls
The things a questionnaire asks about.
These are the four that come up first, in the words they come up in.
One secure sign-in
Single sign-on with multi-factor authentication across every product. Access follows your organization roles, so revoking someone takes one action, not seven.
Encrypted end to end
TLS 1.3 in transit, AES-256 at rest, and encryption keys rotated on a quarterly schedule.
Built to the standards buyers ask about
Engineered against SOC 2 Type II, GDPR, ISO 27001, and PCI DSS requirements, with formal certification targeted as the platform reaches general availability.
Every action accounted for
Administrative actions, permission changes, and support access are logged to an audit trail you can export.
Data residency
Where your data is, and where it is not.
Processing takes place primarily in the United Kingdom and the European Economic Area. Where a processor sits outside those, the transfer runs on UK adequacy regulations, the International Data Transfer Agreement, or the EU Standard Contractual Clauses with a transfer risk assessment.
The list is short because we run our own mail transfer agent, our own media file server and our own databases rather than renting them — every sub-processor is named, with what it does and where, and the page says plainly what is not settled yet rather than leaving a gap that reads as an answer.
Reliability
We commit to 99.9% monthly availability for generally available services, measured from outside the infrastructure it is measuring, with service credits when we miss it.
Products in early access carry no such commitment and the service level agreement says so. Applying one number to everything you sell, including the half-built parts, publishes a number rather than a promise.
- Recovery point objective
- 15 minutes
- Recovery time objective
- 4 hours
- Backup retention
- 35 days
- Breach notification
- 48 hours
Status
All services operating normally
Incidents affecting a generally available service are posted to the changelog and emailed to the administrative contact on every affected organization.
Being honest about this one: A probe-driven status page with historical uptime is not built yet. A stale status page is worse than none, so this is the small honest version until the monitoring behind a real one exists.
Reporting a vulnerability? security@rutba.io. Research on your own organization, without degrading the service for anyone else, is not a breach of our acceptable use policy and we will not pursue you for it.
On request
The long documents, without a form in front of them.
These exist as artefacts rather than web pages, because each is negotiated, countersigned or specific to what you are buying. Ask and a person answers. There is nothing to fill in first, and nothing is withheld until you do.
A completed security questionnaire
SIG or CAIQ shaped, answered rather than deflected
Architecture and data-flow description
For your security review, at the depth it needs
A countersigned DPA
On our paper or yours, with the SCC annexes completed
Penetration test summary
When one exists. It does not yet, and we will say so
Insurance certificates
Professional indemnity and cyber
Business continuity summary
What happens to your service if something happens to us
Send this page to whoever has to approve it.
Then tell us what their questionnaire asks that this page does not answer, and we will answer it — and add it here.