Rulisto Trust Center
Rulisto maintains enterprise-grade security standards. We secure your metadata through strict Row-Level Security (RLS), inherit top-tier compliance certifications from our infrastructure partners, and continuously verify our posture via independent scanning authorities.
Infrastructure & Compliance Architecture
Inherited SOC 2 & ISO 27001
Under the Shared Responsibility Model, Rulisto's data layer and hosting infrastructure are built entirely upon SOC 2 Type II and ISO/IEC 27001 certified providers (Vercel & Supabase/AWS).
CSA STAR Level 1
Rulisto aligns with the Cloud Security Alliance (CSA) best practices. We utilize the Consensus Assessments Initiative Questionnaire (CAIQ) framework to transparently document our cloud security controls.
Automated Vulnerability Scanning
Our CI/CD pipelines enforce strict security gates on every deployment:
- SAST: GitHub CodeQL scans source code for injection flaws and logic vulnerabilities.
- DAST: OWASP ZAP actively probes the production environment.
- Supply Chain: Continuous audits prevent CVEs in third-party dependencies.
Data Residency & Encryption
All metadata is hosted in the US (AWS us-east-1). Data is strictly encrypted at rest using AES-256 and protected in transit utilizing TLS 1.3 cryptography.
Verified Sub-Processors
To minimize third-party risk, Rulisto limits data sharing to SOC 2 certified infrastructure partners. We do not use third-party AI models to train on your compliance data.
Enterprise Security Documentation
Enterprise clients and Agency partners under NDA can request our full CAIQ self-assessment, Data Processing Agreements (DPA), and the latest OWASP ZAP Penetration Test summary report.
Live Cryptographic & Web Security Audits
Mozilla Observatory
HTTP Security Headers & CSP
Validates strict implementation of Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and robust cross-site scripting protections.
View Live Scan Resultsopen_in_newQualys SSL Labs
TLS Cryptography & Trust
Verifies the deployment of strong cryptographic ciphers (TLS 1.3), perfect forward secrecy, strict certificate chains, and vulnerability mitigations (e.g., Heartbleed).
View Live Scan Resultsopen_in_newMalware & Phishing Checks
Google Safe Browsing & VirusTotal
Continuous monitoring via VirusTotal and Google Safe Browsing ensures the platform domain remains strictly unflagged and free of malicious payloads or deceptive UI.
WCAG Accessibility
WAVE & Axe Scans
Rulisto is engineered for broad accessibility, adhering to WCAG 2.1 guidelines to ensure screen-reader compatibility and keyboard navigation across our enterprise dashboards.
Responsible Disclosure Policy (RFC 9116)
Security.txt Implementation
We welcome reports from security researchers and industry experts. We strictly adhere to RFC 9116 standards by publishing a public security.txt file mapping our disclosure channels and reporting policies.
Note on Dynamic IP Resolution: The IP address (e.g., 64.29.17.195) referenced in independent scans corresponds to Vercel's global edge network. Because Rulisto leverages an Anycast CDN, the specific IP audited by SSL Labs may route to a regional edge node, but all nodes universally enforce the same strict A+ TLS policies.