RuleRun

Security

Built for regulated buyers

How we handle your data, how long we keep it, and how access is controlled.

TLS + AES-256 encryption

In transit and at rest

API key access controls

Rotatable, revocable, scoped

Configurable retention

30 days to 12 months

Data handling

  • Email content submitted for compliance runs is stored only for the duration of the run and report retention period.
  • Processed content is isolated per tenant — no cross-tenant data access.
  • All data in transit is encrypted using TLS 1.2+.
  • At rest, data is encrypted using AES-256.

Report retention

  • Free Trial and Starter plans retain reports for 30 days.
  • Pro and Enterprise plans retain reports for 12 months.
  • Reports and associated evidence are automatically deleted after the retention period.
  • You can download reports at any time during the retention window.

Access controls

  • All API requests require a valid API key scoped to your account.
  • API keys can be rotated or revoked at any time from the dashboard.
  • Row-level security ensures each tenant can only access their own data.
  • Authentication is handled via industry-standard JWT tokens.

Compliance posture

  • The platform stores only what is necessary to complete compliance runs and produce audit reports.
  • Audit logs are maintained for all compliance run activity.
  • We do not use your email content to train models or share it with third parties.
  • Data processing agreements are available on request for Enterprise customers.

Need a data processing agreement?

DPAs are available for Enterprise customers. If you have specific security, compliance, or contractual requirements, get in touch.