Legal
Security
An overview of the controls protecting your workspace and the data your clients trust you with.
Last updated 11 August 2026
Encryption
All traffic to Ryzion OS is served over TLS, with HTTP Strict Transport Security enforced across the domain and its subdomains. Data at rest — database records and uploaded media alike — is encrypted by our infrastructure providers using industry-standard ciphers.
Access control
Access inside a workspace is role-based: owners, team members, clients and guests each see only what their role permits, enforced server-side rather than hidden in the interface. Database access is governed by row-level security policies, so a query cannot reach across workspace boundaries even if application code is wrong.
Sign-in supports email and password, one-time codes by SMS, and Google. Authentication endpoints are rate limited to blunt credential-stuffing and brute-force attempts.
Media protection
Photographs and documents are stored in private buckets with no public read access. Delivery goes through our own content-delivery layer, which issues short-lived signed URLs scoped to a single object — so a link that leaks stops working rather than exposing an entire gallery indefinitely, and the underlying storage is never addressed directly by a browser.
Application hardening
We serve a Content Security Policy restricting script, style, image and connection origins, along with X-Content-Type-Options, X-Frame-Options and a restrictive Permissions-Policy. Payment card details are handled entirely by our payment provider and never touch our servers.
Availability and backups
Live component health is published on our status page. Databases are backed up daily and retained for 7 days, and we test a restore at least once a year.
Compliance
We hold no third-party security certification. No SOC 2, ISO 27001 or equivalent audit has been carried out, and we will not imply one. The controls described on this page are ours, implemented and operated by us, and you are welcome to assess them on their merits. Our infrastructure providers hold their own certifications, which cover their platforms rather than this application. If a certification becomes a requirement for you, ask — we would rather hear it than have you assume.
We support customers subject to GDPR and comparable regimes through our Data Processing Addendum.
Reporting a vulnerability
If you believe you have found a security issue, please report it to hello@ryzionos.com before disclosing it publicly. Include enough detail to reproduce the issue. We aim to acknowledge reports within 3 business days and will keep you updated while we investigate.
We ask that you avoid privacy violations, data destruction, and any disruption to the service while researching. We will not pursue legal action against researchers who follow this in good faith.
Incident notification
If a breach affects your personal data, we will notify affected customers and, where required, the relevant supervisory authority within the timescales the law imposes — within 72 hours of becoming aware, where GDPR applies.