hub
Rulisto
Back to Home
shield_locked

Rulisto Trust Center

Rulisto maintains enterprise-grade security standards. We secure your metadata through strict Row-Level Security (RLS), inherit top-tier compliance certifications from our infrastructure partners, and continuously verify our posture via independent scanning authorities.

Infrastructure & Compliance Architecture

verified

Inherited SOC 2 & ISO 27001

Under the Shared Responsibility Model, Rulisto's data layer and hosting infrastructure are built entirely upon SOC 2 Type II and ISO/IEC 27001 certified providers (Vercel & Supabase/AWS).

assignment_turned_in

CSA STAR Level 1

Rulisto aligns with the Cloud Security Alliance (CSA) best practices. We utilize the Consensus Assessments Initiative Questionnaire (CAIQ) framework to transparently document our cloud security controls.

bug_report

Automated Vulnerability Scanning

Our CI/CD pipelines enforce strict security gates on every deployment:

  • SAST: GitHub CodeQL scans source code for injection flaws and logic vulnerabilities.
  • DAST: OWASP ZAP actively probes the production environment.
  • Supply Chain: Continuous audits prevent CVEs in third-party dependencies.

key

Data Residency & Encryption

All metadata is hosted in the US (AWS us-east-1). Data is strictly encrypted at rest using AES-256 and protected in transit utilizing TLS 1.3 cryptography.

dns

Verified Sub-Processors

To minimize third-party risk, Rulisto limits data sharing to SOC 2 certified infrastructure partners. We do not use third-party AI models to train on your compliance data.

Vercel (Hosting)Supabase (Database/Auth)Resend (Emails)Dodo (Payments)

Enterprise Security Documentation

Enterprise clients and Agency partners under NDA can request our full CAIQ self-assessment, Data Processing Agreements (DPA), and the latest OWASP ZAP Penetration Test summary report.

Request Pen Test Report

Live Cryptographic & Web Security Audits

policy

Mozilla Observatory

HTTP Security Headers & CSP

Grade: A+

Validates strict implementation of Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and robust cross-site scripting protections.

View Live Scan Resultsopen_in_new
lock

Qualys SSL Labs

TLS Cryptography & Trust

Grade: A+

Verifies the deployment of strong cryptographic ciphers (TLS 1.3), perfect forward secrecy, strict certificate chains, and vulnerability mitigations (e.g., Heartbleed).

View Live Scan Resultsopen_in_new
shield_locked

Malware & Phishing Checks

Google Safe Browsing & VirusTotal

Status: Clean

Continuous monitoring via VirusTotal and Google Safe Browsing ensures the platform domain remains strictly unflagged and free of malicious payloads or deceptive UI.

accessibility_new

WCAG Accessibility

WAVE & Axe Scans

Compliant

Rulisto is engineered for broad accessibility, adhering to WCAG 2.1 guidelines to ensure screen-reader compatibility and keyboard navigation across our enterprise dashboards.

policy

Responsible Disclosure Policy (RFC 9116)

Security.txt Implementation

We welcome reports from security researchers and industry experts. We strictly adhere to RFC 9116 standards by publishing a public security.txt file mapping our disclosure channels and reporting policies.

View /.well-known/security.txt arrow_right_alt
info

Note on Dynamic IP Resolution: The IP address (e.g., 64.29.17.195) referenced in independent scans corresponds to Vercel's global edge network. Because Rulisto leverages an Anycast CDN, the specific IP audited by SSL Labs may route to a regional edge node, but all nodes universally enforce the same strict A+ TLS policies.