Skip to content
Request evaluation
PricingRequest evaluation

Security posture

Verified controls. Clear boundaries.

RealtrAI protects application access and sensitive server operations with authenticated routes, ownership checks, plan enforcement, and signed webhook processing. We do not market roadmap controls as shipped features.

Ask a security questionResponsible AI review

Current controls

Implemented in the application today.

Authenticated workspace routes

Server-side ownership and team-access checks

Server-side plan and usage enforcement

Signed webhook verification and replay protection

HTTPS production application

Restricted cross-origin policy on the lead API

Current boundaries

What is not being claimed.

  • iRealtrAI is not currently represented as SOC 2 certified.
  • iSAML/OIDC single sign-on and air-gapped deployment are not current product features.
  • iThe current product does not provide a dedicated compliance audit log.
  • iAI-generated drafts require professional review before use.

Attestation path: SOC 2 Type I, then Type II, is the intended attestation sequence for RealtrAI. Until an attestation is issued, procurement teams can request a completed security questionnaire and current implementation details through the contact form; nothing on this page should be read as a certification.

Incident response

A named route, with the evidence boundary stated.

The Chief Technology Officer coordinates technical response and the Chief Legal Officer coordinates legal and notification assessment. Suspected compromise, cross-tenant exposure, unauthorized AI action, harmful output, or loss of required records can be reported through the security contact. We triage by severity, contain affected workflows, preserve evidence, investigate, correct, and notify customers or affected parties within the time required by the applicable agreement and law. This public page does not assert a universal hour-based notification promise or a last-tabletop date that has not been verified.

Dependencies

What this product relies on, and for what.

This website and the lead-capture service run on Render behind Cloudflare - not on group-owned data center capacity - so physical and environmental controls at that layer sit with those providers. The full dated list, with data categories and change notice, is on the subprocessors page.

ProviderRelied on forAttestation status
CloudflareCDN, DNS, TLS edge, and DDoS protection for realtrai.comProvider publishes SOC 2 / ISO attestations; we rely on its published trust documentation
RenderHosting for the static site, the lead API, and the managed PostgreSQL lead databaseProvider publishes SOC 2 attestation; we rely on its published trust documentation
ResendTransactional email delivery for lead and privacy-request notificationsProvider publishes security attestations; we rely on its published trust documentation
StripeBilling, payment processing, and signed billing webhooksPCI DSS Level 1 service provider; we rely on its published compliance documentation
Google Analytics · Meta Pixel · Trunnion AnalyticsOptional, consent-gated analytics and advertising measurementNot configured today (identifiers unset); no data flows even after consent
Foundation-model provider(s)AI generation for product workflowsContracted provider(s) identified in the written agreement and data processing terms

Shared responsibility

What RealtrAI does, what providers do, what you do.

AreaRealtrAIHosting & model providersCustomer
Access controlAuthenticated routes, server-side ownership, team, and plan checksPhysical, network, and platform security at the hosting and CDN layerSeat management and credential hygiene inside your workspace
Data retentionPublished website retention periods and deletion on verified requestStorage durability and provider-side log retentionRetention of drafts and records you export or copy out
Output reviewDraft-only outputs, review guidance, no auto-publishingModel generation within the contracted provider termsProfessional review of every draft before any client or public use
Incident notificationA monitored security contact (security.txt) and notification per the written agreementPlatform incident response at the infrastructure layerReporting suspected issues and acting on notices you receive

FAQ

Security, answered.

How is access controlled?

Application pages require authentication. Server routes enforce record ownership, team membership, and plan entitlements rather than relying on the browser alone.

How are billing and email webhooks protected?

Stripe and Resend webhook signatures are verified, stale or replayed events are rejected, and processed event identifiers are stored for idempotency.

Is RealtrAI SOC 2 certified?

No SOC 2 certification is currently claimed. SOC 2 Type I followed by Type II is the intended attestation path; ask us for the current status, a completed security questionnaire, or specific documentation during procurement.

Where does RealtrAI run?

This website and the lead-capture service run on Render behind Cloudflare. Physical and environmental controls at that layer belong to those providers, and the full dependency list is published on the subprocessors page.

Does RealtrAI offer SSO or air-gapped deployment?

Not in the current public product. These are roadmap or custom-evaluation items and should not be assumed to be available.

How are security incidents handled?

The Chief Technology Officer coordinates technical response and the Chief Legal Officer coordinates legal and notification assessment. Reports are triaged, contained, investigated, and communicated under the applicable agreement and law. No universal notification window in hours or last-tabletop date is claimed on this page; request the current evidence during diligence.

Get started

Have a procurement requirement?

Ask us for the current implementation details before relying on a specific control.

Contact usResponsible AI posture

Necessary technology is always active because it provides security and remembers this choice.