Security Overview
Reelevant maintains a comprehensive Information Security Programme overseen by a dedicated Risk Committee. The programme is reviewed at least annually and covers all aspects of data protection, access control, incident response, and vendor management. For the most up-to-date security documentation, certifications, and audit reports, visit the Reelevant Trust Centre.Certifications & Compliance
The current SOC 2 Type 2 report, those of our hosting providers, and the executive summary of the latest penetration test are available through the Trust Centre under NDA.
No artificial-intelligence feature is part of the service: Reelevant does not train or run AI models on customer data. AI assistance is used only internally, alongside — never instead of — mandatory human review in our development process.
Data Protection
Encryption
Data Residency
- Primary region: EU (additional regions planned) — customer data is stored and processed exclusively in the EU, with no transfer outside the EU
- No customer data outside the EU: the only globally-distributed service is public DNS resolution, which processes no personal data
- Multi-tenant architecture: The platform operates a single production environment with strict logical tenant isolation — each customer’s data is segregated through application-level access controls and scoping
Data Minimisation
- Only fields explicitly mapped in Datasources are accessible to the platform
- No personal data is stored beyond the configured retention period
- Production data is sanitised before use in non-production environments
- No third-party enrichment: the platform never combines your data with external data sources
Personal Data Held by the Platform
Reelevant acts as a data processor on your instructions. The personal data it holds is limited to:
Data exported to the analytics warehouse stays pseudonymous: it carries the customer identifier only, and can be re-identified solely by you through your own reference table.
Retention Controls
- Configurable per Datasource (default 90 days for behavioural events)
- Secure disposal follows industry-accepted standards for data deletion
- Disposal is tracked and documented
- Record-level erasure available on request through the Datasource anonymisation operation
Contractual Commitments
The following commitments are part of the standard Data Processing Agreement (DPA):Access Control
Platform Access
- Two-factor authentication (TOTP) available to every user, and enforceable for all of your users by making SAML SSO mandatory on your domains — authentication policy is then delegated to your own identity provider
- SSO supported via SAML 2.0 — see Authentication & SSO
- RBAC + ABAC — Role-based permissions scoped by company and team attributes
- Least privilege — Users receive the minimum access required for their role
- Quarterly access reviews — All production system access reviewed by management
Password Policy
The password policy is enforced by the platform and configurable per company. Defaults:
Minimum length, character requirements, expiry, password history and lockout thresholds can be tightened to match your own policy. The recommended approach for organisations with a corporate password policy is to delegate authentication entirely to your identity provider through SAML SSO, so that your own rules apply.
Production Systems
- Remote access restricted to authorised personnel; MFA required on all cloud and administrative consoles and on any remote access to production
- SSH key-based authentication only for system-level access — password authentication and root login are disabled, and brute-force protection blocks repeated failed attempts
- Production servers communicate over an encrypted private network that is not reachable from the internet; no RDP or remote desktop access is exposed
- Terminated employees have access revoked within 24 hours, covering identity and device management as well as system-level SSH keys
Vulnerability Management
Scanning & Testing
Remediation Timelines
Patch Management
All system patches are obtained from trusted sources and deployed at least monthly, with critical patches escalated for immediate deployment. Servers apply unattended security updates automatically, with failures reported to the infrastructure team. Workstation and application updates are enforced through device management and applied within 15 days of release.Endpoint & Workplace Security
- Device management — all workstations are enrolled in a mobile device management (MDM) platform that enforces configuration policies, disk encryption, inventory and update cadence. Workstations are not joined to an Active Directory domain
- Endpoint detection and response — next-generation endpoint protection with behavioural detection, automated response and remote isolation of a compromised device, deployed on every workstation
- Corporate identity — accounts and application access are managed in Google Workspace with MFA enforced
- Servers — an antivirus engine is installed on every production host with scheduled scans and centralised reporting of results
- Acceptable use is governed by a published IT policy that applies to all staff
Network & System Security
- Default-deny host firewalls on every server; only the SSH and private-network ports are reachable from the internet
- Encrypted private network between all servers, segmented per environment (production, staging, tooling) and not routable from the internet
- Anti-DDoS protection provided at network level by our hosting provider on all public endpoints
- In-house gateway in front of the API and Runner validates and filters every inbound request (request schema validation, authentication and authorisation checks, restricted route exposure)
- No dedicated next-generation firewall / UTM appliance: perimeter protection relies on the combination of the controls above (host firewalls, provider anti-DDoS, gateway validation, host-based intrusion detection)
- DNSSEC enabled on Reelevant domains
- Host-based intrusion detection and file integrity monitoring on all servers, with alerts and firewall events shipped to centralised, access-controlled log storage
- Secrets management — infrastructure secrets are stored encrypted at rest in an encrypted vault whose key is itself protected, and application secrets are injected at runtime; no secrets are kept in source code
Email & Domain Security
Corporate email runs on Google Workspace with anti-spam and anti-malware filtering, and SPF, DKIM and DMARC are published on Reelevant sending domains.Incident Response
Reelevant maintains a dedicated Incident Response Team (IRT) with defined roles and procedures:- Security events (suspicious activity, no confirmed compromise) — investigated and tracked internally
- Security incidents (confirmed compromise) — full IRT activation, documented investigation, customer notification within 48 hours of detection when personal data is affected
- Annual tabletop exercise to test business continuity and disaster recovery procedures
- Post-incident reports with root cause analysis and remediation actions
Incident Severity Levels
Business Continuity
- Multi-region active-active failover architecture
- Daily full backups of all production data, stored in secure remote locations
- 180-day backup retention with annual restore testing
- Recovery objectives tested annually via tabletop exercises
Vendor Management
Reelevant assesses all vendors for criticality and risk before engagement:- Vendors handling sensitive or confidential data undergo enhanced due diligence
- Critical and high-risk vendors are reviewed at least annually via compliance reports
- All vendors must comply with Reelevant’s information security policies
Infrastructure Vendors
Reelevant runs on a short, deliberately limited list of infrastructure vendors:
OVHcloud and Google Cloud are our only subprocessors of personal data. No other party processes customer data in the delivery of the service.
Subprocessor Details
Legal entities as listed in the DPA:
Neither subprocessor accesses customer data remotely from outside the EU.
Audit Logging
- In-product audit log — authentication, SSO, SCIM provisioning, and user, role and Team changes, readable by your own identity administrators
- Security logs centrally collected and retained for 1 year in access-controlled storage, in line with the CNIL recommendation for log retention
- Monitoring model — centralised logging with automated alerting and an on-call engineering rotation; Reelevant does not operate a commercial SIEM nor a third-party 24/7 SOC
- Log forwarding to your SOC / SIEM — available in beta; contact your account team
- All admin actions logged with user attribution and timestamp
- Authentication events (successful and failed) captured and monitored
- File integrity monitoring and host-based intrusion detection deployed
- Log data protected for confidentiality, integrity, and availability
Reporting a Security Issue
security@reelevant.com is the single entry point for any security or data protection request — vulnerability reports, incident notifications and data subject requests.
No Data Protection Officer has been appointed, as designation is not mandatory under Article 37 for our processing activities. Article 30 record-keeping obligations and processing details are covered in customer contracts and the DPA.
Legal entity: Reelevant SAS, 10 rue de Penthièvre, 75008 Paris, France — RCS Paris 521 917 468.
Include reproduction steps and affected endpoints where possible. Reports are triaged by the Incident Response Team and remediated according to the timelines above.
Security Awareness
- All employees complete security awareness training within 30 days of hire
- Annual refresher training required
- Background checks performed on all new hires
- Confidentiality agreements signed before system access is granted
- Specialised secure-development training for engineers, with OWASP practices shared across the team
- Security is owned by the CTO with a Risk Committee and Incident Response Team, and reinforced by external assurance (annual SOC 2 audit, annual external penetration test, continuous automated scanning)
Learn More
Trust Centre
Up-to-date certifications, audit reports, and security documentation.
Status Page
Real-time platform availability and incident history.
Releases & Backward Compatibility
Release policy, notice periods, and compatibility guarantees.