Secure by design
Security decisions are made while a feature is being designed — not bolted on afterwards. New surfaces are reviewed for what data they touch and who can reach them.
RapidRoot automates the work around customer conversations — enquiries, bookings, reminders, payments — so boundaries matter more than badges. This centre explains how security, tenancy and product maturity are actually handled today.
Practices in place today are labelled. Planned work is labelled as planned. No invented SOC 2, ISO or HIPAA claims.
We reinforce trust by labelling honest state on every surface, including pricing and docs.
TLS 1.2 or higher on all dashboard and API traffic.
Workspace roles enforced on the server, not in the interface.
On the roadmap. Not available today.
No third-party audit or certification has been completed.
Plain-language rules that shape how features get built and how the platform is operated.
Security decisions are made while a feature is being designed — not bolted on afterwards. New surfaces are reviewed for what data they touch and who can reach them.
People and services get the narrowest access that lets them do their job. Credentials are scoped per environment and can be rotated or revoked.
We assume any single control can fail. Network boundaries, application authorisation and workspace-level roles each enforce access independently.
Traffic between customers, our dashboard and our APIs is encrypted in transit. Secrets are stored in managed secret storage rather than in source code.
Application and infrastructure logs are collected so unusual behaviour and failures can be investigated rather than guessed at.
We would rather hear about a problem than discover it later. Researchers can report issues directly and we will acknowledge and investigate them.
Customer Operations means handling live workflows — messages, calls, stays and bookings. Trust comes from boundaries that are honest: who can access what, which data is isolated where, and where money movement is verified.
Individual accounts, workspace roles, server-enforced checks and rotatable, environment-scoped credentials. No shared logins for attribution.
Access controlData is scoped to the workspace it belongs to. Every request is workspace-checked server-side — not trusted from the client. See Data protection & Infrastructure.
Hostel and Real Estate billing follows the existing backend implementation — payment verification and entitlements are server-side; no client-side amount trust. See Compliance roadmap.
Compliance roadmapEach page covers one area in detail, and says plainly where a control does not exist yet.
What data we hold, why we hold it, and how it is handled.
Transport security and credential handling, at a high level.
Accounts, roles, sessions and authentication.
A plain-language view of collection, purpose and control.
Hosting, scaling, logging and monitoring architecture.
Monitoring, incident detection and planned maintenance.
Backup strategy, recovery philosophy and continuity goals.
How issues are reported, handled and communicated.
Human oversight, transparency and appropriate AI use.
How we intend to build and operate AI features.
Current practices separated clearly from future goals.
Common security, privacy and procurement questions.
Privacy Policy, Terms, Cookies and Acceptable Use.
Reporting a vulnerability and what to expect.
RapidRoot secures the platform, its infrastructure and the APIs we operate. Customers are responsible for how they configure their workspace: who they invite, what data they route through the platform, how they store credentials, and whether their messaging has consent.
Messaging and voice delivery depend on third-party network and messaging providers, which operate under their own terms and security practices.
Space is reserved for documents we intend to publish. None of them exist yet, and we will not reference them as evidence until they do.
Planned — a deeper technical description of platform controls.
Planned — detailed data-flow diagrams for security review.
Planned — will be published only if and when a test is performed.
Planned — periodic reporting on automated conversation quality.
Planned — incidents, availability and data requests over time.