Architecture & security
Security & Architecture
We describe our architecture rather than advertise certifications we have not obtained. Everything below refers to how the applications are built and operated.
Architecture
How the applications are built
Multi-tenant isolation
Each customer operates inside an isolated organisational environment. Data, users, configuration and reporting are scoped to a tenant at the application layer.
Role-based access control
Permissions are granted by role, and roles are scoped to the tenant, team and function that requires them.
Authentication
Local accounts, LDAP or Active Directory, or federated sign-in through your own SAML identity provider.
API authentication and scoping
Integrations authenticate with issued credentials limited to specific endpoints and data, and can be revoked independently.
Audit logging
Security-relevant actions are recorded with the acting user, the affected record and a timestamp.
Encryption in transit
Application and API traffic is served over TLS. Connector traffic to your systems uses the transport your environment requires.
Session management
Configurable session lifetime, idle expiry and revocation, applied per organisation.
Least privilege
Default roles grant the narrowest useful access; broader permissions are an explicit administrative decision.
Rate limiting
Per-credential request thresholds protect the platform from a single misbehaving integration.
Secure file handling
Uploads are constrained by type and size, stored outside the web root and served through permission checks.
Retention control
Retention periods are configurable per organisation and per data type, with legal-hold exceptions where required.
Deployment options
Applications can be hosted by RingLyft or deployed inside your own infrastructure, including per-product deployment.
Tenancy model
How multi-tenancy works
Every application follows the same tenancy model, which is what allows a BPO to run many clients inside one deployment.
Application
One deployment of a single product.
Organisation / tenant
An isolated environment: its own configuration, users and data.
Teams, departments, users
Roles and permissions scoped inside the organisation.
Data isolation
Records are bound to their organisation on every query.
Transparency
What we do not claim
RingLyft does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS or GDPR certification. Where your procurement process requires a formal attestation, tell us during evaluation and we will state precisely what can and cannot be provided.
What we will provide during an evaluation
- A written description of the tenancy and access model for the products under evaluation.
- The role and permission matrix as it will be configured for your organisation.
- Details of what each requested connector reads and writes, and with which credentials.
- Deployment options, including hosting inside your own infrastructure.
- An honest answer about anything we do not yet support.
Reporting a vulnerability
If you believe you have found a security issue in a RingLyft application or in this website, write to security@ringlyft.com with enough detail to reproduce it. We will confirm receipt and keep you informed while we investigate.
Send us your security questionnaire.
We answer procurement and information-security questionnaires directly, and we mark clearly anything that is not yet in place.