Security at Rupt

You send us signals about the people using your product. Here is what we do with them, where they live, and how to reach us about it.

Compliance

SOC 2

Audited controls covering security, availability, and confidentiality. The report is available to customers and active evaluations under NDA.

GDPR

Rupt acts as a processor for the data you send us. A data processing agreement and our current sub-processor list are available on request.

How your data is handled

In transit and at rest
Every request to the Rupt API is encrypted in transit. Stored data is encrypted at rest.
Identity matching
Person matching runs on keyed HMAC indexes rather than the underlying values, so the same person resolves consistently across evaluations without the original being readable from the database. KYC document fields are encrypted individually with AES-256-GCM.
Retention
Evaluation data is retained for 30 days on Premium. Enterprise plans can set retention up to 18 months.
Access
Access to production is limited to the engineers who need it, and Enterprise plans get role-based permissions for your own team.

Where Rupt runs

Rupt runs on Google Cloud, in a single region in the United States. That is true of the API, the hosted challenge pages, and the datastores behind them.

If a privacy assessment or a regulator requires your data to be processed somewhere else, tell us where and we will scope it with you. Get in touch and we will send the sub-processor list and our DPA alongside it.

Reporting a vulnerability

Email security@rupt.dev with what you found and the steps to reproduce it. We read every report and will confirm we received yours.

Please test against your own account and your own project. Do not run automated scans against production, and do not access or modify data that is not yours.