Security
Our security programme, certifications, and disclosure process.
Last updated
Security is a continuous practice at Relnivo, not a checklist. This page describes the controls in place and how to report a vulnerability.
Certifications
- SOC 2 Type II — audited annually, report available under NDA
- ISO 27001 — certified information security management system
- GDPR — DPA with standard contractual clauses available to all customers
- Annual third-party penetration testing with summary reports on request
Infrastructure
Relnivo runs on hardened cloud infrastructure with network isolation, least-privilege service accounts, and no standing production access for engineers. All access is brokered, time-limited, and logged.
Encryption
TLS 1.3 in transit and AES-256 at rest. Enterprise customers may supply their own encryption keys, with rotation controlled from their own key management system.
Access control
Role-based permissions extend to individual fields. SAML 2.0 and OIDC single sign-on with SCIM provisioning are available on Business and Enterprise plans, and every read and write is recorded in an exportable audit log.
Resilience
Point-in-time recovery with a 35-day window, multi-zone redundancy, and quarterly restore drills. Our published recovery objectives are one hour RTO and five minutes RPO.
Reporting a vulnerability
Email security@relnivo.com with reproduction steps. We acknowledge within one business day, keep you updated through remediation, and operate a bug bounty for qualifying reports. We do not pursue legal action against good-faith research conducted under our disclosure policy.