Security Policy
Last updated: August 11, 2026
Ruligent is designed as a control and evidence layer for AI-agent operations. Security is implemented through layered application, identity, data, deployment, and governance controls, but no service can guarantee absolute security.
1. Current controls
- TLS for public endpoints and strict transport/security headers in production.
- Organization-scoped authorization and tenant-aware database access.
- Passwords protected with modern password hashing and API/session credentials stored as non-reversible digests where applicable.
- Signed webhook delivery and verification mechanisms.
- Fail-closed behavior for conflicting security-sensitive configuration aliases.
- Governed deployment workflows, automated tests, security review gates, and rollback procedures.
- Production health monitoring and Postgres-backed persistent storage.
2. Customer responsibilities
Customers are responsible for protecting their own credentials, limiting agent permissions, configuring appropriate policies and approvals, reviewing high-impact actions, securing webhook endpoints, and routing relevant actions through Ruligent. Ruligent cannot protect actions that bypass the service.
3. Security claims
Ruligent does not claim SOC 2, ISO 27001, FedRAMP, HIPAA certification, PCI DSS service-provider certification, or any other external certification unless the live Security page expressly states that certification has been obtained. Product controls and internal tests are not substitutes for independent certification.
4. Vulnerability reporting
If you believe you have found a security vulnerability, report it through the Ruligent contact page. Include enough information to reproduce the issue without sending live credentials or unnecessary personal data. Good-faith testing should avoid privacy violations, destructive actions, persistence, data exfiltration, denial-of-service activity, and access to data beyond what is necessary to demonstrate the issue.
5. Incident handling
Security incidents are handled under the Incident Response Policy. Depending on severity, mitigations may include credential rotation, rollback, route restriction, integration isolation, or temporary service limitation.
6. Security contact
Security inquiries and vulnerability reports can be submitted through the Ruligent contact page.