RUDY AI
Security

Security designed for enterprise workforce data.

RUDY protects employee data with encryption, tenant isolation, access control, and annual penetration testing — built for the trust requirements of sensitive HR intelligence.

Data encryption

All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed separately from data using a dedicated key management service. No plain-text PII is stored in application logs.

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Separate key management service
  • Zero plain-text PII in logs

Access control

RUDY implements role-based access control (RBAC) with the principle of least privilege. SSO and SAML 2.0 are supported. All access events are logged and auditable.

  • Role-based access control (RBAC)
  • Least-privilege design
  • SSO / SAML 2.0 support
  • Access event logging

Infrastructure

RUDY's infrastructure is hosted in the US with geographic redundancy. Tenant isolation ensures no data crossover between organizations. RUDY aligns with SOC 2 Type II controls.

  • US-based hosting
  • Tenant isolation architecture
  • SOC 2 Type II alignment
  • No third-party data sharing

Vulnerability management

Dependency vulnerabilities are scanned on every build and tracked to resolution. A third-party penetration test is planned before general availability; we will publish the summary when there is one.

  • Dependency scanning in CI
  • Third-party pentest planned pre-GA
  • Responsible disclosure welcomed
  • Remediation tracked in the changelog

Incident response

RUDY maintains a documented incident response program with 24-hour notification SLAs for qualifying data events, breach investigation protocols, and forensic support.

  • 24-hour notification SLA
  • Documented breach protocol
  • Forensic investigation support
  • Customer communication templates

Privacy by design

PII is pseudonymized in all processing pipelines. Aggregation thresholds prevent individual inference from group data. Data minimization is enforced at the collection layer.

  • PII pseudonymization
  • Aggregation thresholds enforced
  • Data minimization at collection
  • Purpose limitation controls

Enterprise security documentation

Request our architecture and data-flow summary, our AI governance model, and a data processing agreement. We do not yet have an audit report or a penetration test summary to share, and we would rather tell you that now than at procurement.

View Trust Center

See RUDY AI in action.

Explore real workforce intelligence, privacy-first AI coaching, and manager-ready insights in our live demo environment.

No surveillance. No black-box scoring. Human review where it matters.