Skip to main content

Security Overview

Reelevant maintains a comprehensive Information Security Programme overseen by a dedicated Risk Committee. The programme is reviewed at least annually and covers all aspects of data protection, access control, incident response, and vendor management. For the most up-to-date security documentation, certifications, and audit reports, visit the Reelevant Trust Centre.

Certifications & Compliance

Data Protection

Encryption

Data Residency

  • Primary region: EU (additional regions planned)
  • Multi-tenant architecture: The platform operates a single production environment with strict logical tenant isolation — each customer’s data is segregated through application-level access controls and scoping

Data Minimisation

  • Only fields explicitly mapped in Datasources are accessible to the platform
  • No personal data is stored beyond the configured retention period
  • Production data is sanitised before use in non-production environments

Retention Controls

  • Configurable per Datasource (default 90 days for behavioural events)
  • Secure disposal follows industry-accepted standards for data deletion
  • Disposal is tracked and documented

Access Control

Platform Access

  • Multi-factor authentication (MFA) required for all users
  • SSO supported via SAML 2.0 — see Authentication & SSO
  • RBAC + ABAC — Role-based permissions scoped by company and team attributes
  • Least privilege — Users receive the minimum access required for their role
  • Quarterly access reviews — All production system access reviewed by management

Production Systems

  • Remote access restricted to authorised personnel with valid MFA token
  • VPN (IPSec / SSL) required for all remote production access
  • SSH key-based authentication for system-level access
  • Terminated employees have access revoked within 24 hours

Vulnerability Management

Scanning & Testing

Remediation Timelines

Patch Management

All system patches are obtained from trusted sources and deployed at least monthly, with critical patches escalated for immediate deployment.

Incident Response

Reelevant maintains a dedicated Incident Response Team (IRT) with defined roles and procedures:
  • Security events (suspicious activity, no confirmed compromise) — investigated and tracked internally
  • Security incidents (confirmed compromise) — full IRT activation, documented investigation, customer notification if required
  • Annual tabletop exercise to test business continuity and disaster recovery procedures
  • Post-incident reports with root cause analysis and remediation actions

Incident Severity Levels

Business Continuity

  • Multi-region active-active failover architecture
  • Daily full backups of all production data, stored in secure remote locations
  • 180-day backup retention with annual restore testing
  • Recovery objectives tested annually via tabletop exercises

Vendor Management

Reelevant assesses all vendors for criticality and risk before engagement:
  • Vendors handling sensitive or confidential data undergo enhanced due diligence
  • Critical and high-risk vendors are reviewed at least annually via compliance reports
  • All vendors must comply with Reelevant’s information security policies

Infrastructure Vendors

Reelevant runs on a short, deliberately limited list of infrastructure vendors:

Audit Logging

  • Audit logs retained for 1 year
  • All admin actions logged with user attribution and timestamp
  • Authentication events (successful and failed) captured and monitored
  • File integrity monitoring and host-based intrusion detection deployed
  • Log data protected for confidentiality, integrity, and availability

Reporting a Security Issue

Report suspected vulnerabilities or security incidents to security@reelevant.com. Include reproduction steps and affected endpoints where possible. Reports are triaged by the Incident Response Team and remediated according to the timelines above.

Security Awareness

  • All employees complete security awareness training within 30 days of hire
  • Annual refresher training required
  • Background checks performed on all new hires
  • Confidentiality agreements signed before system access is granted

Learn More

Trust Centre

Up-to-date certifications, audit reports, and security documentation.

Status Page

Real-time platform availability and incident history.

Releases & Backward Compatibility

Release policy, notice periods, and compatibility guarantees.