RPRED PALM

Security

Security Overview

The practices and controls RED PALM uses to protect customer data across DECISION ENGINE.

Effective date: [TODO — set at launch] · Applies to DECISION ENGINE and redpalm.ai

Overview

Security is foundational to DECISION ENGINE. This page summarizes our technical and organizational measures. Statements marked as TODO depend on final infrastructure details and will be completed before launch. Report security issues to security@redpalm.ai.

01.Infrastructure Security

DECISION ENGINE runs on reputable cloud infrastructure with network isolation, firewalls, and hardened configurations.

TODO before launch

Complete with the final infrastructure details:

  • Name the cloud provider(s) and hosting regions.
  • Describe network segmentation and environment separation (production vs. staging).

02.Encryption

In transit: all traffic between your browser and the service is encrypted with TLS.

At rest: customer data is encrypted at rest where supported by the underlying infrastructure, using industry-standard algorithms (such as AES-256).

03.Authentication

Accounts are protected by authenticated sessions and industry-standard password handling (passwords are hashed, never stored in plaintext).

TODO before launch

Document MFA availability, session lifetimes, and SSO options (if offered) before launch.

04.Backups

Customer data is backed up on a regular schedule so the service can be restored in the event of failure.

TODO before launch
  • Backup frequency and retention.
  • Backup encryption and storage location.
  • Restore testing cadence.

05.Access Controls

Access to customer data is limited to authorized Red Palm personnel on a least-privilege basis. Access is granted only when necessary for customer support, maintenance, troubleshooting, security, or legal compliance, and is logged.

06.Monitoring & Logging

We log administrative and system activity, monitor for anomalies, and alert on suspicious behavior. Logs are protected against tampering and retained per our retention schedule.

07.Incident Response

We maintain an incident response process covering identification, containment, eradication, recovery, and post-incident review. Where an incident affects your data, we will notify you without undue delay, consistent with applicable law and the DPA.

08.Disaster Recovery

Recovery procedures are designed to restore service from backups in the event of a major failure.

TODO before launch
  • Recovery time objective (RTO) and recovery point objective (RPO).
  • Failover / multi-region posture.

09.Employee Access & Training

Personnel with access to customer data are bound by confidentiality obligations and receive security awareness guidance. Access is reviewed and revoked promptly on role change or departure.

10.Secure Development Lifecycle

Changes go through code review and testing before release. Dependencies are monitored for known vulnerabilities, secrets are kept out of source control, and production access is restricted.

11.Reporting a Vulnerability

If you believe you have found a security issue, email security@redpalm.ai. Good-faith research is protected under our Vulnerability Disclosure Policy.

FAQ

Is my data encrypted?

Yes — TLS for all data in transit, and encryption at rest where supported by the underlying infrastructure, using industry-standard algorithms.

Who can access my data inside Red Palm?

Only authorized personnel, on a least-privilege basis, when necessary for support, maintenance, troubleshooting, security, or legal compliance. Access is logged.

Where is my data stored?

Hosting locations depend on our infrastructure providers and will be documented on this page and in the Subprocessor List before launch.

Related policies