RPRED PALM

Red Palm · Decision Engine

Legal & Trust Center

Everything you need to know about how RED PALM protects customer data, operates DECISION ENGINE, and manages security, privacy, compliance, billing, and legal policies.

TLS in transitEncrypted at rest*Least-privilege accessMonth to monthYou own everything

Quick answers

The questions buyers ask first

Short answers up front, full policies one click deeper. Items marked TODO are completed before launch — never guessed.

Is my data encrypted?

Yes. Traffic is encrypted in transit with TLS, and data is encrypted at rest where supported by the underlying infrastructure, following industry-standard security practices.

Learn more →

Who can see my data?

Only authorized RED PALM personnel, on a least-privilege basis, and only when necessary for support, maintenance, troubleshooting, security, or legal compliance.

Learn more →
TODO before launch

Do you train AI models on my data?

This answer must accurately document our AI providers, prompt retention, model training, customer-data usage, and opt-outs before launch — we will not ship a vague answer here.

Learn more →
TODO before launch

Where is my data stored?

Depends on final infrastructure. To be documented: cloud provider(s), hosting regions, backup locations, and disaster recovery posture.

Learn more →

Who are your subprocessors?

A small set of vetted vendors — hosting, payments, AI, call tracking, email — each under contract to protect your data. The full list is public and kept current.

Learn more →

Can I sign a DPA?

Yes. Enterprise customers may request a countersigned Data Processing Addendum, including Standard Contractual Clauses where applicable.

Learn more →

What’s your uptime?

Availability commitments are documented in our Service Level Agreement. A public status page is planned. status.redpalm.ai · [TODO]

Learn more →

How do I report a security issue?

security@redpalm.ai is the official security contact. Good-faith research is protected by safe harbor.

Learn more →

Compliance

Compliance

Where we stand today, stated plainly: framework alignment now, formal certifications as we grow. Badges below are roadmap markers, not certification claims.

Framework alignment

GDPR

Processor terms, SCC-based transfers, and data-subject rights support through our DPA and Privacy Policy.

Framework alignment

CCPA / CPRA

Service-provider terms, no sale of personal information, and California rights handling.

Coming soon

SOC 2

A SOC 2 examination is on our roadmap. This card will link to the report when it is available.

Future

ISO 27001

ISO 27001 certification is under evaluation as the company scales.

In progress

Privacy Frameworks

Standard Contractual Clauses and the UK Addendum are used for international transfers where required.

Need additional legal or security information?

Security questionnaires, signed DPAs, vendor reviews, or anything this page doesn’t answer — we respond fast.

*Encryption at rest where supported by the underlying infrastructure — see the Security Overview.