Where we are, and where we are going
This page separates what RapidRoot does today from what we intend to do. Nothing in the future column should be read as a current capability.
Current certification status
This page is maintained by RapidRoot to answer common security and privacy questions about our platform. It describes practices that are in place today and clearly labels anything that is planned. It is not a certification, an audit result, or independent verification.
RapidRoot does not currently hold SOC 2, ISO 27001, HIPAA, PCI DSS or any equivalent certification, and has not completed an independent third-party security audit. Any document or claim suggesting otherwise is not from us.
In place today
TLS for all platform traffic
In place todayDashboard and API traffic is encrypted in transit.
Role-based workspace access
In place todayServer-enforced roles and permissions per workspace.
Scoped, rotatable credentials
In place todayEnvironment-scoped API keys that can be revoked.
Managed, patched infrastructure
In place todayManaged cloud services with provider-level hardening and backups.
Centralised logging and alerting
In place todayOperational visibility across application and delivery events.
Responsible disclosure channel
In place todayA published security contact with a defined response process.
In progress
Written internal security policies
In progressFormalising access, change and incident procedures as written policy.
Customer-visible audit log
In progressExpanding admin event capture into a viewable trail.
Documented recovery runbooks
In progressRepeatable, tested restore procedures.
Published subprocessor list
In progressA versioned list of providers involved in processing customer data.
Future goals
Independent security assessment
PlannedAn external review or penetration test, with a summary published if performed.
Multi-factor authentication and SSO
PlannedStronger authentication options for enterprise workspaces.
Data processing agreements at scale
PlannedA standard DPA available on request, with defined subprocessor notification.
Formal certification programme
PlannedA recognised framework such as SOC 2 or ISO 27001 once the underlying practices are consistently evidenced.
Transparency reporting
PlannedPeriodic reporting on incidents, uptime and data requests.
If a specific control is a blocker for your evaluation, tell us. We would rather give you an honest timeline than a vague reassurance.