Architecture & security

Security & Architecture

We describe our architecture rather than advertise certifications we have not obtained. Everything below refers to how the applications are built and operated.

Architecture

How the applications are built

Multi-tenant isolation

Each customer operates inside an isolated organisational environment. Data, users, configuration and reporting are scoped to a tenant at the application layer.

Role-based access control

Permissions are granted by role, and roles are scoped to the tenant, team and function that requires them.

Authentication

Local accounts, LDAP or Active Directory, or federated sign-in through your own SAML identity provider.

API authentication and scoping

Integrations authenticate with issued credentials limited to specific endpoints and data, and can be revoked independently.

Audit logging

Security-relevant actions are recorded with the acting user, the affected record and a timestamp.

Encryption in transit

Application and API traffic is served over TLS. Connector traffic to your systems uses the transport your environment requires.

Session management

Configurable session lifetime, idle expiry and revocation, applied per organisation.

Least privilege

Default roles grant the narrowest useful access; broader permissions are an explicit administrative decision.

Rate limiting

Per-credential request thresholds protect the platform from a single misbehaving integration.

Secure file handling

Uploads are constrained by type and size, stored outside the web root and served through permission checks.

Retention control

Retention periods are configurable per organisation and per data type, with legal-hold exceptions where required.

Deployment options

Applications can be hosted by RingLyft or deployed inside your own infrastructure, including per-product deployment.

Tenancy model

How multi-tenancy works

Every application follows the same tenancy model, which is what allows a BPO to run many clients inside one deployment.

Application

One deployment of a single product.

Organisation / tenant

An isolated environment: its own configuration, users and data.

Teams, departments, users

Roles and permissions scoped inside the organisation.

Data isolation

Records are bound to their organisation on every query.

Transparency

What we do not claim

RingLyft does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS or GDPR certification. Where your procurement process requires a formal attestation, tell us during evaluation and we will state precisely what can and cannot be provided.

What we will provide during an evaluation

  • A written description of the tenancy and access model for the products under evaluation.
  • The role and permission matrix as it will be configured for your organisation.
  • Details of what each requested connector reads and writes, and with which credentials.
  • Deployment options, including hosting inside your own infrastructure.
  • An honest answer about anything we do not yet support.

Reporting a vulnerability

If you believe you have found a security issue in a RingLyft application or in this website, write to security@ringlyft.com with enough detail to reproduce it. We will confirm receipt and keep you informed while we investigate.

Send us your security questionnaire.

We answer procurement and information-security questionnaires directly, and we mark clearly anything that is not yet in place.