/ TRUST CENTER

Security &
Compliance.

RuleAI.Systems handles the operational data that manufacturers, quality departments, and industrial operators use to run their business. Below is a plain-language summary of how we protect it, what standards we align to today, and what we’re pursuing next.

Last updated: February 2026 · Version 1.0
◆ LIVE COMMITMENTS

What we do today, in production.

Encryption in transit

All traffic to RuleAI.Systems is served over TLS 1.2 or newer. Modern cipher suites only. HTTP is rejected at the edge.

Encryption at rest

Production data lives in MongoDB Atlas with AES-256 encryption at rest on managed storage volumes.

Password hashing

User passwords are hashed with bcrypt (cost factor ≥ 12). Plaintext passwords are never logged or stored.

Token-based authentication

Session tokens are signed JWTs with an expiration window. All authenticated API calls verify signature and expiration.

Role-based access control

Multi-tenant workspace isolation. Owner / Admin / Editor / Viewer roles enforced at every API endpoint. No data crosses org boundaries.

Immutable audit log

Every SOP action, record change, approval, and comment is logged with actor identity, timestamp, and before/after state.

Redundant hosting

Application infrastructure runs across multiple availability zones. Automatic failover and load balancing at the ingress layer.

Backup & recovery

Automated daily snapshots of production data. Point-in-time recovery available. Recovery point objective ≤ 24 hours.

Environment isolation

Production, preview, and development environments are fully isolated. No production data ever crosses into non-production.

Vulnerability response

We accept responsible disclosure at security@ruleai.systems. Critical vulnerabilities are triaged within 24 hours; remediated within 7 days.

/ DATA HANDLING

Your data, plainly explained.

Where is my data stored?

All production data is stored in the United States on managed cloud infrastructure (MongoDB Atlas). Enterprise customers can request a dedicated instance region.

Does RuleAI train AI models on my data?

No. Content you or your team enter into RuleAI is never used to train third-party or in-house AI models. When you invoke an AI feature, only the specific request payload is sent to the model provider (Anthropic Claude Sonnet 4.6), and no training data agreement is granted.

Which third-party sub-processors do you use?

MongoDB Atlas (data storage, US), Anthropic Claude (AI features), Stripe (payments, when enabled). We do not resell your data to any third party.

Can I export my data?

Yes. Every SOP, record, comment, and spreadsheet you create can be exported to CSV, PDF, or DOCX at any time. Enterprise customers get bulk export tools.

What happens if I close my account?

Your active data is retained for 30 days after account closure to allow recovery, then permanently deleted from our production systems. Backups are purged within 90 days.

How do you handle personal data (GDPR / CCPA)?

We collect only what’s necessary to operate the service: email, name, organization, and product usage. Users can request deletion or export by emailing support@ruleai.systems.

/ COMPLIANCE ROADMAP

What we’re pursuing next.

We publish our compliance posture honestly. Below is where we are today, and where we’re headed. We do not claim certifications we do not hold.

GDPR / CCPA data handling
Aligned
Data subject rights supported by export + deletion via support ticket.
ISO 27001 alignment
In progress
Internal controls audited quarterly. Formal certification targeted 2026 Q4.
SOC 2 Type I
Targeted 2026 Q4
Engagement to begin with a licensed auditor after we cross 100 paying customers.
SOC 2 Type II
Targeted 2027
Follows successful Type I engagement, 6-month observation window.
ISO 9001 (internal QMS)
Live via RuleAI
We eat our own dog food — RuleAI is our own QMS.
HIPAA (for healthcare enterprise)
On request
BAAs available for enterprise healthcare customers. Contact sales.

Security questions?

Enterprise buyers can request our security questionnaire responses, our SIG Lite, and a call with the founders.