R&L Automations

Legal and trust

Security and Incident Response

Effective and last updated: July 29, 2026

Our security program is designed around limited access, tenant separation, controlled communications, observable failures, and safe shutdown.

Core controls

  • Separate staging and production environments with deployment provenance and rollback records.
  • Least-privilege runtime roles, tenant-scoped database policies, and managed credentials kept out of client-side code and source control.
  • Provider-authenticated webhooks, replay and duplicate handling, bounded retries, and durable dead-letter review.
  • Recipient allowlists for controlled testing, tenant-specific sender configuration, consent and suppression checks, quiet hours, spend caps, and kill switches.
  • Logs and evidence designed to omit credentials, message bodies, and unnecessary personal information.

Incident response

We contain unsafe activity, preserve appropriate evidence, assess affected systems and tenants, rotate credentials where needed, restore from a verified release, and document corrective actions. Confirmed incidents are communicated to affected contracted clients without undue delay and in accordance with the applicable agreement and law.

Reporting a concern

Contact support@rlbusinessautomations.com. Do not send passwords, tokens, customer records, or exploit payloads by email.