rulint
Trust & Data Handling

Start with the minimum information necessary.

Compliance testing can involve sensitive information. Rulint's approach begins by separating non-confidential scoping from the governed client workflows used during an engagement.

Public Intake

The public testing-request form is intended only for initial, non-confidential scoping information.

  • Do not submit customer information
  • Do not submit production data or files
  • Do not submit privileged legal information
  • Detailed evidence is not required for an initial conversation

Client Engagement Data

Data requirements should be driven by the approved testing methodology, not by collecting information simply because it is available.

  • Define the testing population and required fields
  • Identify required supporting evidence
  • Establish the approved transfer method
  • Limit access to the engagement need

Governed Access

Rulint maintains separate authenticated client and administrative workflows for operational testing activities rather than conducting client testing through the public website.

Vendor & Security Review

Security, access, data-transfer, retention, and other vendor-diligence requirements can be addressed during scoping before production client data is accepted for an engagement.

Claims & Certifications

Rulint does not rely on unsupported security claims.

Public security statements are intended to reflect controls and practices that Rulint can substantiate. Formal certifications or examination results will be identified specifically if and when they are completed.

Before Production Data

Security and data requirements should be agreed before testing begins.

The exact information required depends on the testing scope, systems, population, evidence, and client environment. Those requirements are established during engagement scoping rather than through the public form.