rulint
Trust & Data Handling

Security and data handling are part of the testing methodology.

Independent compliance testing can involve sensitive information. Rulint separates public scoping from authenticated client workflows, limits information requests to the testing need, and applies governed access and evidence-handling controls throughout the engagement.

Core Principles

Collect what is needed. Control who can access it. Preserve the testing record.

Data Minimization

Information requests are driven by the approved testing methodology, population, evidence requirements, and testing objective rather than by collecting data simply because it is available.

Authenticated Workspaces

Client testing activities occur through authenticated client and administrative workflows rather than through the public website.

Traceable Activity

Testing activity, evidence handling, review decisions, and lifecycle actions are structured to preserve an auditable record of the work.

Data Handling Lifecycle

Information moves through a governed engagement path.

1 Non-Confidential Scoping Initial discussions begin with the testing need and do not require production customer data or evidence files.
2 Defined Data Requirement Rulint establishes the required population fields, evidence, documentation, and transfer method based on the testing methodology.
3 Authenticated Exchange Client data, evidence, responses, and testing collaboration move through authenticated engagement workflows.
4 Governed Testing Record Evidence, results, findings, responses, approvals, and reporting remain connected to the engagement record.
Implemented Controls

Current controls supporting Rulint access and evidence handling.

The controls below describe capabilities currently implemented within the Rulint application and evidence workflow.

1

Multi-Factor Authentication

Administrative access uses password plus TOTP authentication. Client portal access also requires enrolled multi-factor authentication.

2

Controlled Sessions

Administrative and client sessions enforce idle and absolute session limits, with secure session-cookie configuration.

3

Client / Admin Separation

Rulint maintains distinct authenticated administrative and client workflows so client collaboration is separated from internal testing administration.

4

Encrypted S3 Evidence Storage

Where S3 evidence storage is used, Rulint applies AWS KMS server-side encryption to stored evidence objects.

5

Controlled Evidence Downloads

S3 evidence access uses short-lived presigned download links and performs security validation before evidence is made available.

6

Audit & Backup Support

Rulint maintains application audit logging and database backup capability to support operational traceability and recovery.

Security Transparency

Public claims should match implemented controls.

Rulint does not present planned capabilities or future certifications as completed controls. Formal certifications, independent examination results, or additional security attestations will be identified specifically when they have been completed and are available to support the claim.

Vendor & Security Diligence

Security requirements can be addressed before production data is accepted.

The exact data and security requirements depend on the engagement, systems involved, population, evidence, client environment, and applicable vendor-management requirements.

Authentication and access-control review
Data-flow and evidence-transfer requirements
Data minimization and required-field review
Evidence-storage and access requirements
Retention and deletion expectations
Client-specific vendor diligence requirements
Before Testing Begins

Establish the testing and data-handling requirements first.

Initial scoping can begin without confidential client data. Production information and evidence should be provided only after the engagement, testing methodology, data requirements, and approved exchange method have been established.