Security posture
Verified controls. Clear boundaries.
RealtrAI protects application access and sensitive server operations with authenticated routes, ownership checks, plan enforcement, and signed webhook processing. We do not market roadmap controls as shipped features.
Current controls
Implemented in the application today.
Authenticated workspace routes
Server-side ownership and team-access checks
Server-side plan and usage enforcement
Signed webhook verification and replay protection
HTTPS production application
Restricted cross-origin policy on the lead API
Current boundaries
What is not being claimed.
- iRealtrAI is not currently represented as SOC 2 certified.
- iSAML/OIDC single sign-on and air-gapped deployment are not current product features.
- iThe current product does not provide a dedicated compliance audit log.
- iAI-generated drafts require professional review before use.
Attestation path: SOC 2 Type I, then Type II, is the intended attestation sequence for RealtrAI. Until an attestation is issued, procurement teams can request a completed security questionnaire and current implementation details through the contact form; nothing on this page should be read as a certification.
Incident response
A named route, with the evidence boundary stated.
The Chief Technology Officer coordinates technical response and the Chief Legal Officer coordinates legal and notification assessment. Suspected compromise, cross-tenant exposure, unauthorized AI action, harmful output, or loss of required records can be reported through the security contact. We triage by severity, contain affected workflows, preserve evidence, investigate, correct, and notify customers or affected parties within the time required by the applicable agreement and law. This public page does not assert a universal hour-based notification promise or a last-tabletop date that has not been verified.
Dependencies
What this product relies on, and for what.
This website and the lead-capture service run on Render behind Cloudflare - not on group-owned data center capacity - so physical and environmental controls at that layer sit with those providers. The full dated list, with data categories and change notice, is on the subprocessors page.
| Provider | Relied on for | Attestation status |
|---|---|---|
| Cloudflare | CDN, DNS, TLS edge, and DDoS protection for realtrai.com | Provider publishes SOC 2 / ISO attestations; we rely on its published trust documentation |
| Render | Hosting for the static site, the lead API, and the managed PostgreSQL lead database | Provider publishes SOC 2 attestation; we rely on its published trust documentation |
| Resend | Transactional email delivery for lead and privacy-request notifications | Provider publishes security attestations; we rely on its published trust documentation |
| Stripe | Billing, payment processing, and signed billing webhooks | PCI DSS Level 1 service provider; we rely on its published compliance documentation |
| Google Analytics · Meta Pixel · Trunnion Analytics | Optional, consent-gated analytics and advertising measurement | Not configured today (identifiers unset); no data flows even after consent |
| Foundation-model provider(s) | AI generation for product workflows | Contracted provider(s) identified in the written agreement and data processing terms |
Shared responsibility
What RealtrAI does, what providers do, what you do.
| Area | RealtrAI | Hosting & model providers | Customer |
|---|---|---|---|
| Access control | Authenticated routes, server-side ownership, team, and plan checks | Physical, network, and platform security at the hosting and CDN layer | Seat management and credential hygiene inside your workspace |
| Data retention | Published website retention periods and deletion on verified request | Storage durability and provider-side log retention | Retention of drafts and records you export or copy out |
| Output review | Draft-only outputs, review guidance, no auto-publishing | Model generation within the contracted provider terms | Professional review of every draft before any client or public use |
| Incident notification | A monitored security contact (security.txt) and notification per the written agreement | Platform incident response at the infrastructure layer | Reporting suspected issues and acting on notices you receive |
FAQ
Security, answered.
How is access controlled?
Application pages require authentication. Server routes enforce record ownership, team membership, and plan entitlements rather than relying on the browser alone.
How are billing and email webhooks protected?
Stripe and Resend webhook signatures are verified, stale or replayed events are rejected, and processed event identifiers are stored for idempotency.
Is RealtrAI SOC 2 certified?
No SOC 2 certification is currently claimed. SOC 2 Type I followed by Type II is the intended attestation path; ask us for the current status, a completed security questionnaire, or specific documentation during procurement.
Where does RealtrAI run?
This website and the lead-capture service run on Render behind Cloudflare. Physical and environmental controls at that layer belong to those providers, and the full dependency list is published on the subprocessors page.
Does RealtrAI offer SSO or air-gapped deployment?
Not in the current public product. These are roadmap or custom-evaluation items and should not be assumed to be available.
How are security incidents handled?
The Chief Technology Officer coordinates technical response and the Chief Legal Officer coordinates legal and notification assessment. Reports are triaged, contained, investigated, and communicated under the applicable agreement and law. No universal notification window in hours or last-tabletop date is claimed on this page; request the current evidence during diligence.
Get started
Have a procurement requirement?
Ask us for the current implementation details before relying on a specific control.
