Security and data handling are part of the testing methodology.
Independent compliance testing can involve sensitive information. Rulint separates public scoping from authenticated client workflows, limits information requests to the testing need, and applies governed access and evidence-handling controls throughout the engagement.
Collect what is needed. Control who can access it. Preserve the testing record.
Data Minimization
Information requests are driven by the approved testing methodology, population, evidence requirements, and testing objective rather than by collecting data simply because it is available.
Authenticated Workspaces
Client testing activities occur through authenticated client and administrative workflows rather than through the public website.
Traceable Activity
Testing activity, evidence handling, review decisions, and lifecycle actions are structured to preserve an auditable record of the work.
Information moves through a governed engagement path.
Current controls supporting Rulint access and evidence handling.
The controls below describe capabilities currently implemented within the Rulint application and evidence workflow.
Multi-Factor Authentication
Administrative access uses password plus TOTP authentication. Client portal access also requires enrolled multi-factor authentication.
Controlled Sessions
Administrative and client sessions enforce idle and absolute session limits, with secure session-cookie configuration.
Client / Admin Separation
Rulint maintains distinct authenticated administrative and client workflows so client collaboration is separated from internal testing administration.
Encrypted S3 Evidence Storage
Where S3 evidence storage is used, Rulint applies AWS KMS server-side encryption to stored evidence objects.
Controlled Evidence Downloads
S3 evidence access uses short-lived presigned download links and performs security validation before evidence is made available.
Audit & Backup Support
Rulint maintains application audit logging and database backup capability to support operational traceability and recovery.
Public claims should match implemented controls.
Rulint does not present planned capabilities or future certifications as completed controls. Formal certifications, independent examination results, or additional security attestations will be identified specifically when they have been completed and are available to support the claim.
Security requirements can be addressed before production data is accepted.
The exact data and security requirements depend on the engagement, systems involved, population, evidence, client environment, and applicable vendor-management requirements.
Establish the testing and data-handling requirements first.
Initial scoping can begin without confidential client data. Production information and evidence should be provided only after the engagement, testing methodology, data requirements, and approved exchange method have been established.