RuleAI.Systems handles the operational data that manufacturers, quality departments, and industrial operators use to run their business. Below is a plain-language summary of how we protect it, what standards we align to today, and what we’re pursuing next.
All traffic to RuleAI.Systems is served over TLS 1.2 or newer. Modern cipher suites only. HTTP is rejected at the edge.
Production data lives in MongoDB Atlas with AES-256 encryption at rest on managed storage volumes.
User passwords are hashed with bcrypt (cost factor ≥ 12). Plaintext passwords are never logged or stored.
Session tokens are signed JWTs with an expiration window. All authenticated API calls verify signature and expiration.
Multi-tenant workspace isolation. Owner / Admin / Editor / Viewer roles enforced at every API endpoint. No data crosses org boundaries.
Every SOP action, record change, approval, and comment is logged with actor identity, timestamp, and before/after state.
Application infrastructure runs across multiple availability zones. Automatic failover and load balancing at the ingress layer.
Automated daily snapshots of production data. Point-in-time recovery available. Recovery point objective ≤ 24 hours.
Production, preview, and development environments are fully isolated. No production data ever crosses into non-production.
We accept responsible disclosure at security@ruleai.systems. Critical vulnerabilities are triaged within 24 hours; remediated within 7 days.
All production data is stored in the United States on managed cloud infrastructure (MongoDB Atlas). Enterprise customers can request a dedicated instance region.
No. Content you or your team enter into RuleAI is never used to train third-party or in-house AI models. When you invoke an AI feature, only the specific request payload is sent to the model provider (Anthropic Claude Sonnet 4.6), and no training data agreement is granted.
MongoDB Atlas (data storage, US), Anthropic Claude (AI features), Stripe (payments, when enabled). We do not resell your data to any third party.
Yes. Every SOP, record, comment, and spreadsheet you create can be exported to CSV, PDF, or DOCX at any time. Enterprise customers get bulk export tools.
Your active data is retained for 30 days after account closure to allow recovery, then permanently deleted from our production systems. Backups are purged within 90 days.
We collect only what’s necessary to operate the service: email, name, organization, and product usage. Users can request deletion or export by emailing support@ruleai.systems.
We publish our compliance posture honestly. Below is where we are today, and where we’re headed. We do not claim certifications we do not hold.