Security & Trust
How we protect your data
RuleResource is built for healthcare compliance teams, so we designed it around the data you can and cannot put in it, and around your control over what you do put in.
We do not process protected health information
RuleResource is a regulatory research and compliance-management platform. It is not a clinical system and is architecturally designed so that Protected Health Information (PHI) is never required and should not be submitted. Our research, screening, and analysis features operate on regulatory sources and publicly available datasets, not patient records.
Encryption
Data is encrypted in transit with TLS. Sensitive fields, including case descriptions, findings, and screening details, are encrypted at rest with AES-256-GCM field-level encryption, in addition to encryption at the database layer. Encryption keys are held as platform secrets, separate from the application database.
Your organization's identity is not sent to the analysis engine
When we personalize an analysis using your organization's profile, identifying details, including your organization's name, are stripped before the request reaches the language-processing engine. The engine receives categorical context (for example, "a mid-sized behavioral health organization operating in Texas"), not your identity. Analysis providers operate under agreements that prohibit training on your data and provide for zero data retention.
Access control
Access is governed by role-based access control with distinct roles (administrator, compliance officer, privacy officer, manager, user, and read-only viewer) and a granular permission model. Every account signs in with a password and a code from an authenticator app (two-factor, TOTP): it is required for every user and cannot be turned off. Each code is accepted once, repeated wrong attempts are locked out, and sessions end on sign-out or a password change. Every organization's data is isolated at the row level.
Audit logging
High-signal actions are written to an append-only audit trail (who did what, and when), available to administrators and retained as a compliance record. Screening logs, case activity, and administrative changes are all captured.
Hosting and subprocessors
The platform runs on Cloudflare's edge network with a Neon PostgreSQL database (encrypted at rest). We use a small set of subprocessors: Cloudflare (hosting), Neon (database), Resend (email), Stripe (billing), and a third-party language-processing provider for research synthesis (under a no-training, zero-retention agreement). We do not sell your data.
Your right to deletion
You can erase your account and personal data at any time from your account settings. On request, we remove your identifying information and disable access. You control your data; researching a regulatory question creates a record that belongs to your organization, and you decide how long to keep it.
Reporting a concern
If you believe you have found a security issue, contact us at security@ruleresource.com. We take reports seriously and will respond promptly.
This page describes our current security practices and is provided for information. It is not a contract or a warranty. Specific commitments are governed by your agreement with us.