Platform security

How does RUMvision protect the platform?

Account security is only one part of protecting customer data.

RUMvision also applies technical and organisational measures to protect the application, customer accounts and the data processed through our platform against unauthorised access, loss and misuse.

Encryption

Data is encrypted both in transit and at rest.

Connections to the RUMvision application and APIs are encrypted in transit, while stored data and backups are protected using encryption at rest.

Passwords are not stored in plain text. They are securely hashed before storage.

Restricted internal access

Access to production systems is limited to employees who need it for their role.

Internal access uses individual accounts rather than shared credentials and is protected with two-factor authentication.

We have processes for granting and removing access, permissions are reviewed periodically, and administrative access to production systems is logged.

Customer and domain separation

Customer data is logically separated between accounts and domains.

Access to RUM data is permission-based within the application and underlying systems, so users only receive access to the domains and data they are authorised to use.

RUMvision employees only access customer data where this is necessary for activities such as support, troubleshooting, security or service operations.

Monitoring and protection against misuse

We monitor our systems for suspicious or abnormal activity and use controls intended to reduce common forms of abuse.

These measures include:

  • rate limiting and protection against repeated authentication attempts
  • security and account activity logging
  • vulnerability and dependency scanning
  • controlled software updates and security patching
  • security reviews around significant releases

Backups and recovery

We maintain encrypted backups of important systems and data.

Backups are stored separately from the primary environment. Retention depends on the type of backup and can extend up to one year where applicable.

We also maintain disaster recovery procedures and test our ability to restore from backups.

Development and release security

RUMvision uses separate production, staging and development environments.

We perform vulnerability and dependency checks and follow an update and patching process to address identified issues.

Significant releases are subject to security review as part of our development and deployment process.

Incident response

We maintain procedures for responding to security incidents and potential personal data breaches.

If an incident affects personal data that we process on behalf of a customer, we handle notification and cooperation in accordance with our Data Processing Agreement and applicable data protection law.

Security is an ongoing process

No online service can eliminate every security risk. We therefore treat security as an ongoing process rather than a one-time implementation.

We review access, monitor our infrastructure, update dependencies and systems, test recovery procedures and adjust safeguards as the RUMvision platform develops.

For contractual information about security, subprocessors and data protection obligations, see our privacy and legal documentation.