Skip to content
Compliance roadmap

Where we are, and where we are going

This page separates what RapidRoot does today from what we intend to do. Nothing in the future column should be read as a current capability.

Current certification status

How to read this page

This page is maintained by RapidRoot to answer common security and privacy questions about our platform. It describes practices that are in place today and clearly labels anything that is planned. It is not a certification, an audit result, or independent verification.

No certifications held

RapidRoot does not currently hold SOC 2, ISO 27001, HIPAA, PCI DSS or any equivalent certification, and has not completed an independent third-party security audit. Any document or claim suggesting otherwise is not from us.

In place today

TLS for all platform traffic

In place today

Dashboard and API traffic is encrypted in transit.

Role-based workspace access

In place today

Server-enforced roles and permissions per workspace.

Scoped, rotatable credentials

In place today

Environment-scoped API keys that can be revoked.

Managed, patched infrastructure

In place today

Managed cloud services with provider-level hardening and backups.

Centralised logging and alerting

In place today

Operational visibility across application and delivery events.

Responsible disclosure channel

In place today

A published security contact with a defined response process.

In progress

Written internal security policies

In progress

Formalising access, change and incident procedures as written policy.

Customer-visible audit log

In progress

Expanding admin event capture into a viewable trail.

Documented recovery runbooks

In progress

Repeatable, tested restore procedures.

Published subprocessor list

In progress

A versioned list of providers involved in processing customer data.

Future goals

Independent security assessment

Planned

An external review or penetration test, with a summary published if performed.

Multi-factor authentication and SSO

Planned

Stronger authentication options for enterprise workspaces.

Data processing agreements at scale

Planned

A standard DPA available on request, with defined subprocessor notification.

Formal certification programme

Planned

A recognised framework such as SOC 2 or ISO 27001 once the underlying practices are consistently evidenced.

Transparency reporting

Planned

Periodic reporting on incidents, uptime and data requests.

Procurement conversations

If a specific control is a blocker for your evaluation, tell us. We would rather give you an honest timeline than a vague reassurance.