Legal and trust
Security and Incident Response
Effective and last updated: July 29, 2026
Our security program is designed around limited access, tenant separation, controlled communications, observable failures, and safe shutdown.
Core controls
- Separate staging and production environments with deployment provenance and rollback records.
- Least-privilege runtime roles, tenant-scoped database policies, and managed credentials kept out of client-side code and source control.
- Provider-authenticated webhooks, replay and duplicate handling, bounded retries, and durable dead-letter review.
- Recipient allowlists for controlled testing, tenant-specific sender configuration, consent and suppression checks, quiet hours, spend caps, and kill switches.
- Logs and evidence designed to omit credentials, message bodies, and unnecessary personal information.
Incident response
We contain unsafe activity, preserve appropriate evidence, assess affected systems and tenants, rotate credentials where needed, restore from a verified release, and document corrective actions. Confirmed incidents are communicated to affected contracted clients without undue delay and in accordance with the applicable agreement and law.
Reporting a concern
Contact support@rlbusinessautomations.com. Do not send passwords, tokens, customer records, or exploit payloads by email.
