Security Overview
Reelevant maintains a comprehensive Information Security Programme overseen by a dedicated Risk Committee. The programme is reviewed at least annually and covers all aspects of data protection, access control, incident response, and vendor management. For the most up-to-date security documentation, certifications, and audit reports, visit the Reelevant Trust Centre.Certifications & Compliance
Data Protection
Encryption
Data Residency
- Primary region: EU (additional regions planned)
- Multi-tenant architecture: The platform operates a single production environment with strict logical tenant isolation — each customer’s data is segregated through application-level access controls and scoping
Data Minimisation
- Only fields explicitly mapped in Datasources are accessible to the platform
- No personal data is stored beyond the configured retention period
- Production data is sanitised before use in non-production environments
Retention Controls
- Configurable per Datasource (default 90 days for behavioural events)
- Secure disposal follows industry-accepted standards for data deletion
- Disposal is tracked and documented
Access Control
Platform Access
- Multi-factor authentication (MFA) required for all users
- SSO supported via SAML 2.0 — see Authentication & SSO
- RBAC + ABAC — Role-based permissions scoped by company and team attributes
- Least privilege — Users receive the minimum access required for their role
- Quarterly access reviews — All production system access reviewed by management
Production Systems
- Remote access restricted to authorised personnel with valid MFA token
- VPN (IPSec / SSL) required for all remote production access
- SSH key-based authentication for system-level access
- Terminated employees have access revoked within 24 hours
Vulnerability Management
Scanning & Testing
Remediation Timelines
Patch Management
All system patches are obtained from trusted sources and deployed at least monthly, with critical patches escalated for immediate deployment.Incident Response
Reelevant maintains a dedicated Incident Response Team (IRT) with defined roles and procedures:- Security events (suspicious activity, no confirmed compromise) — investigated and tracked internally
- Security incidents (confirmed compromise) — full IRT activation, documented investigation, customer notification if required
- Annual tabletop exercise to test business continuity and disaster recovery procedures
- Post-incident reports with root cause analysis and remediation actions
Incident Severity Levels
Business Continuity
- Multi-region active-active failover architecture
- Daily full backups of all production data, stored in secure remote locations
- 180-day backup retention with annual restore testing
- Recovery objectives tested annually via tabletop exercises
Vendor Management
Reelevant assesses all vendors for criticality and risk before engagement:- Vendors handling sensitive or confidential data undergo enhanced due diligence
- Critical and high-risk vendors are reviewed at least annually via compliance reports
- All vendors must comply with Reelevant’s information security policies
Infrastructure Vendors
Reelevant runs on a short, deliberately limited list of infrastructure vendors:Audit Logging
- Audit logs retained for 1 year
- All admin actions logged with user attribution and timestamp
- Authentication events (successful and failed) captured and monitored
- File integrity monitoring and host-based intrusion detection deployed
- Log data protected for confidentiality, integrity, and availability
Reporting a Security Issue
Report suspected vulnerabilities or security incidents to security@reelevant.com.
Include reproduction steps and affected endpoints where possible. Reports are triaged by the Incident Response Team and remediated according to the timelines above.
Security Awareness
- All employees complete security awareness training within 30 days of hire
- Annual refresher training required
- Background checks performed on all new hires
- Confidentiality agreements signed before system access is granted
Learn More
Trust Centre
Up-to-date certifications, audit reports, and security documentation.
Status Page
Real-time platform availability and incident history.
Releases & Backward Compatibility
Release policy, notice periods, and compatibility guarantees.