Security designed for enterprise workforce data.
RUDY protects employee data with encryption, tenant isolation, access control, and annual penetration testing — built for the trust requirements of sensitive HR intelligence.
Data encryption
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed separately from data using a dedicated key management service. No plain-text PII is stored in application logs.
- AES-256 encryption at rest
- TLS 1.3 in transit
- Separate key management service
- Zero plain-text PII in logs
Access control
RUDY implements role-based access control (RBAC) with the principle of least privilege. SSO and SAML 2.0 are supported. All access events are logged and auditable.
- Role-based access control (RBAC)
- Least-privilege design
- SSO / SAML 2.0 support
- Access event logging
Infrastructure
RUDY's infrastructure is hosted in the US with geographic redundancy. Tenant isolation ensures no data crossover between organizations. RUDY aligns with SOC 2 Type II controls.
- US-based hosting
- Tenant isolation architecture
- SOC 2 Type II alignment
- No third-party data sharing
Vulnerability management
Dependency vulnerabilities are scanned on every build and tracked to resolution. A third-party penetration test is planned before general availability; we will publish the summary when there is one.
- Dependency scanning in CI
- Third-party pentest planned pre-GA
- Responsible disclosure welcomed
- Remediation tracked in the changelog
Incident response
RUDY maintains a documented incident response program with 24-hour notification SLAs for qualifying data events, breach investigation protocols, and forensic support.
- 24-hour notification SLA
- Documented breach protocol
- Forensic investigation support
- Customer communication templates
Privacy by design
PII is pseudonymized in all processing pipelines. Aggregation thresholds prevent individual inference from group data. Data minimization is enforced at the collection layer.
- PII pseudonymization
- Aggregation thresholds enforced
- Data minimization at collection
- Purpose limitation controls
Enterprise security documentation
Request our architecture and data-flow summary, our AI governance model, and a data processing agreement. We do not yet have an audit report or a penetration test summary to share, and we would rather tell you that now than at procurement.
View Trust CenterSee RUDY AI in action.
Explore real workforce intelligence, privacy-first AI coaching, and manager-ready insights in our live demo environment.
No surveillance. No black-box scoring. Human review where it matters.
