Security

Rallyware builds a comprehensive data protection system by combining organizational and technical measures. Our approach is based on the five SOC 2 Trust Service Criteria: security, availability, processing integrity, confidentiality and privacy. We place special emphasis on safeguarding client and personal data, continuously enhancing our measures to meet contractual requirements. A key proof of effectiveness is the absence of any client data breaches.

Modern cyber threats require not only reactive but also proactive solutions. That is why we implement monitoring systems, dynamic processes, and continuous oversight. All measures are documented in our Information Security Management System (ISMS), which is updated annually and reviewed through internal and external audits.

Each year, we conduct independent penetration testing to identify and mitigate potential risks. Our employees serve as the first line of defense, and we actively foster a strong security culture.

Personnel and Training

Security begins with people. Before hiring, we verify education, references, and, when necessary, conduct additional checks such as criminal records. All employees sign an NDA on their first day and complete basic information security training.

Mandatory security training is held annually and is regularly updated based on our risk analysis. Our employees also attend specialized courses, participate in international conferences, and obtain professional certifications.

Vulnerability Management

Rallyware actively protects its systems from the exploitation of vulnerabilities. We use scanners for both internal and external perimeters, classify vulnerabilities by severity, and respond promptly to identified issues. The security team constantly monitors alerts from vendors and professional resources about new risks and threats. This approach enables us to minimize potential risks at the earliest stages.

Endpoint Protection

We follow the principle of “defense in depth”. Each device is equipped with MDM solutions, corporate antivirus, full-disk encryption, host firewalls, and other security controls to ensure comprehensive protection. This approach enables centralized device management, enforcement of security policies, and timely response to potential threats. Our antivirus system leverages cloud technologies and behavioral analytics, allowing detection of even hidden attacks.

Incident Management

The incident response process is developed in accordance with international information security standards. All employees are familiar with the incident reporting procedure. The incident response team prioritizes cases based on their impact on client data. After each incident, a root cause analysis is conducted, and corrective actions are implemented to prevent recurrence in the future.

Identification and Authorization

We apply modern access management methods: all accounts are protected with multi-factor authentication, and access rights are assigned according to roles (RBAC). This ensures a controlled and transparent distribution of access to corporate resources.

Network and IT Infrastructure

Rallyware’s infrastructure is built on AWS, following established security best practices. Each service is designed and maintained with reliability and data protection requirements in mind. Project environments are isolated, traffic is always encrypted, and access is secured with multi-factor authentication. For network protection, we use advanced tools such as NGFW, WAF, VPN and other solutions that provide resilience and control.

Business Continuity and Recovery

To ensure uninterrupted operations, Rallyware has developed and regularly tests BCP and DRP plans. These cover scenarios such as pandemics, crisis communication, and disaster recovery. 

Bug Bounty Program

Our company prioritizes the security of our customers’ data. We understand that even the best processes and technologies need constant testing, so we have introduced the Bug Bounty Program, a vulnerability bounty program.

The purpose of the program:

  • To provide an additional layer of protection for our products and services.
  • To create a transparent channel of communication with independent security researchers.
  • To receive information about potential risks in a timely manner and eliminate them before they can be used by attackers.

How it works:

  • Security researchers can test our public services and products.
  • If a vulnerability is discovered, they report it directly to [email protected]  .
  • We promptly analyze the message, confirm the finding and determine the level of criticality.
  • The researcher receives a reward according to the vulnerability category.

Program rules:

  • DoS/DDoS attacks, social engineering and physical intrusions are prohibited.
  • We expect responsible disclosure: the researcher is not allowed to publish details until the vulnerability is fixed.

We appreciate everyone who helps us make our products more secure. Your contribution is part of our shared mission to protect data and customer trust.

Summary

Rallyware builds security at every level — from infrastructure and processes to employee training. We continuously enhance our protection measures to meet client requirements and international standards. The company’s primary focus is reliability, confidentiality, and business continuity.