Security first architecture

RMUR is designed as a multi tenant software platform with security boundaries considered from the beginning. The architecture is intended to separate organization data, limit access by role and preserve a clear record of important actions.

Identity and access

RMUR's planned access model includes individual user identities, role based permissions, strong authentication, audit logging and support for modern business identity requirements. Access is intended to follow the principle of least privilege.

Data protection

RMUR uses or plans to use appropriate safeguards for data in transit, stored data, administrative access, backups and service operations. Sensitive information is limited to authorized processes and people who require it for legitimate service delivery.

Monitoring and logging

Operational and security events are monitored to support reliability, abuse prevention, investigation and response. Important administrative actions are intended to be recorded so RMUR can understand what happened, when it happened and which identity performed the action.

Secure development

RMUR development follows review, testing and controlled release practices appropriate to the feature and risk. Dependencies, configuration, access controls and changes that affect customer security receive additional scrutiny.

Incident response

RMUR maintains an approach for identifying, containing, investigating and recovering from security incidents. If an incident creates a material risk to affected customers, RMUR will communicate according to applicable obligations and the circumstances of the event.

Customer responsibilities

Security responsibilities depend on the selected plan. Monitor customers remain responsible for completing recommended changes. Protect adds guided hardening and provider handoffs. Managed SOC customers authorize RMUR to review serious supported alerts and handle agreed response work with the access needed to act. Complete adds an ongoing testing and improvement program. Every customer remains responsible for approved users, accurate ownership information, secure account credentials and prompt notice of suspicious activity.

Responsible vulnerability reporting

If you believe you have found a security issue involving RMUR, do not access customer data, disrupt service, download information or publicly disclose the issue before RMUR can investigate. Provide the affected page or feature, a clear description and safe reproduction details through the RMUR Contact page.

Report a security concern

Open the secure contact form