01.Infrastructure Security
DECISION ENGINE runs on reputable cloud infrastructure with network isolation, firewalls, and hardened configurations.
Complete with the final infrastructure details:
- Name the cloud provider(s) and hosting regions.
- Describe network segmentation and environment separation (production vs. staging).
02.Encryption
In transit: all traffic between your browser and the service is encrypted with TLS.
At rest: customer data is encrypted at rest where supported by the underlying infrastructure, using industry-standard algorithms (such as AES-256).
03.Authentication
Accounts are protected by authenticated sessions and industry-standard password handling (passwords are hashed, never stored in plaintext).
Document MFA availability, session lifetimes, and SSO options (if offered) before launch.
04.Backups
Customer data is backed up on a regular schedule so the service can be restored in the event of failure.
- Backup frequency and retention.
- Backup encryption and storage location.
- Restore testing cadence.
05.Access Controls
Access to customer data is limited to authorized Red Palm personnel on a least-privilege basis. Access is granted only when necessary for customer support, maintenance, troubleshooting, security, or legal compliance, and is logged.
06.Monitoring & Logging
We log administrative and system activity, monitor for anomalies, and alert on suspicious behavior. Logs are protected against tampering and retained per our retention schedule.
07.Incident Response
We maintain an incident response process covering identification, containment, eradication, recovery, and post-incident review. Where an incident affects your data, we will notify you without undue delay, consistent with applicable law and the DPA.
08.Disaster Recovery
Recovery procedures are designed to restore service from backups in the event of a major failure.
- Recovery time objective (RTO) and recovery point objective (RPO).
- Failover / multi-region posture.
09.Employee Access & Training
Personnel with access to customer data are bound by confidentiality obligations and receive security awareness guidance. Access is reviewed and revoked promptly on role change or departure.
10.Secure Development Lifecycle
Changes go through code review and testing before release. Dependencies are monitored for known vulnerabilities, secrets are kept out of source control, and production access is restricted.
11.Reporting a Vulnerability
If you believe you have found a security issue, email security@redpalm.ai. Good-faith research is protected under our Vulnerability Disclosure Policy.