RMSAutomation
Pricing Back to site

Security & Data

Effective 31 July 2026  ·  RMS Automation LLC

On this page

  1. Encryption
  2. Tenant isolation
  3. Authentication and access
  4. Audit trail
  5. Infrastructure
  6. Backups and continuity
  7. Data handling in AI processing
  8. Your data, your control
  9. Incident response
  10. Reporting a vulnerability
  11. Your responsibilities

This page describes controls that are in place today. It is not a compliance certification. If you need a signed security questionnaire, a DPA or a penetration-test summary for your own audit, write to us and we will provide what we have.

01Encryption

All traffic runs over TLS 1.2 or higher with modern cipher suites; HTTP is redirected to HTTPS and HSTS is enabled. Data at rest — including uploaded photographs and generated PDFs — is encrypted with AES-256 on managed storage.

02Tenant isolation

RMS Automation is multi-tenant. Every record carries an organisation identifier, and every query is scoped to the organisation of the authenticated caller at the data-access layer rather than in individual handlers. Uploaded files are served through an authenticated, organisation-scoped route — never from a public directory — and requests for another organisation's file are rejected before the file is read.

03Authentication and access

  • Passwords are hashed with a memory-hard algorithm and a per-user salt. We never store them in plain text and cannot recover them.
  • API access uses bearer tokens scoped to one organisation, revocable at any time.
  • Roles separate owner and worker permissions; workers cannot reach billing or organisation settings.
  • Internal administrative access is limited to staff who need it, is individually attributed, and is logged.

04Audit trail

Test records keep a full history rather than only the latest state. Creating, editing, finalising, locking, unlocking and exporting a test cycle are each recorded with actor and timestamp. Unlocking a finalised cycle is a deliberate, logged action — so a record cannot be quietly changed after sign-off.

05Infrastructure

The platform runs on managed cloud infrastructure in the United States. Databases are not publicly routable. Secrets are held in environment configuration, never in source control, and are rotated on staff change or suspected exposure. Dependencies are monitored for known vulnerabilities and patched on a risk-based schedule.

06Backups and continuity

Databases are backed up daily with point-in-time recovery. Backups are encrypted and access-controlled, and restores are tested periodically. Backup retention is 90 days.

07Data handling in AI processing

Content sent to model providers for extraction is covered by agreements that prohibit training on your data and limit retention to what is needed to serve the request. Extraction results are returned to you for review before they are written to a record. See the Privacy Policy for detail.

08Your data, your control

  • Export — your records, at any time, in open formats including PowerDB-compatible CSV and PDF.
  • Deletion — delete individual records, or close your account to remove everything.
  • Retention after closure — 30 days in live systems for restore or export, then deletion; encrypted backups age out within a further 90 days.

09Incident response

We maintain an incident process covering detection, containment, eradication and review. If a breach affects your personal data we will notify you without undue delay and within any statutory deadline that applies, with what we know, what we are doing, and what you should do.

10Reporting a vulnerability

Email security@rmsautomation.com with steps to reproduce and any supporting detail. We acknowledge within two business days and will keep you updated until it is resolved.

Please give us reasonable time to fix an issue before disclosing it, do not access or modify data that is not yours, and do not degrade the Service for other users. We will not pursue legal action for good-faith research that follows these guidelines.

11Your responsibilities

Security is shared. Use a strong, unique password. Remove seats promptly when someone leaves. Keep API tokens out of source control and rotate them if exposed. Review extracted values before you sign off on them.

© 2026 RMS Automation LLC. All rights reserved.
Terms of Service Privacy Policy Cookie Policy Acceptable Use Home
RMS Automation