Security & trust

Your risk data is sensitive. We treat it that way.

A risk register is a map of an organisation's weakest points. Rukn ERM is built so that map stays private — protected in transit, isolated per tenant, and locked down to the right people.

Controls in the product

How we protect your data

Encryption in transit

All traffic between the app and our servers is encrypted over HTTPS/TLS. Data at rest sits in managed, access-controlled databases.

Role-based access

Granular roles decide who can view, edit, approve or administer. People see only what their role allows.

Optional MFA

Turn on multi-factor authentication per user for a second layer beyond the password on every sign-in.

Biometric app lock

On mobile, require Face ID / fingerprint to open the app — so a picked-up phone doesn't expose your register.

Per-tenant isolation

Every organisation's data is scoped to its own tenant. Requests are authorised against your organisation — never another's.

Session visibility & revocation

See every device signed in to your account and sign any of them out individually, or all at once. A password reset ends every session. Revocation stops further access within five minutes at most.

Uploads & evidence

Safe handling of attachments

Evidence and documents are validated on upload — file types are checked against their actual content, dangerous types are blocked, and file names are sanitised before storage. Attachments are scoped to the record and tenant they belong to.

  • Content-type verificationMagic-byte checks, not just the extension.
  • Dangerous types blockedExecutables and scripts are rejected.
  • Filename sanitisationNames are cleaned before they touch disk.
Hosting & portability

A managed cloud service — your data stays yours

Rukn ERM runs as a managed cloud service on access-controlled infrastructure. Every organisation's data is isolated to its own tenant, encrypted in transit, and exportable at any time — your register, reports and records are never locked in. If you have specific data-residency requirements, talk to us.

Talk to us
Cloud (SaaS)

Hosted and managed by Rukn ERM. Fastest to start, no infrastructure to run.

Data portability

Export your register and reports whenever you need — including a full export if you ever decide to leave.

Security FAQ

Questions we get asked

Where is my data hosted?

Your data is hosted on managed, access-controlled cloud infrastructure, isolated per tenant. We'll confirm the specific hosting region and arrangement as part of onboarding.

Can I control who sees what?

Yes. Role-based access control lets you decide who can view, edit, approve or administer each area, and every request is authorised against your organisation only.

Do you support multi-factor authentication?

Yes — MFA is available and can be enabled per user as an optional second factor on sign-in.

Does the AI assistant send my data anywhere risky?

The assistant answers only from your own organisation's records and is read-only. If your policy requires it, the AI feature can be disabled for your organisation; the rest of the platform works without it.

Can we run a security review before buying?

Absolutely. Contact us and we'll walk your security team through the architecture, controls and deployment options.

Have a security or compliance question?

We're happy to walk your team through how Rukn ERM protects your data.