Last reviewed: 2026-08-08
RNDBI Work is an invitation-only beta operated by a small team. Rather than answer a security questionnaire with the vague language a young product usually reaches for, this page states plainly what is in place and what is not. Everything in the second list is work in progress, not a hidden defect - a firm evaluating RNDBI Work should be able to weigh both halves before deciding whether the beta is appropriate for its data.
If your firm has a security questionnaire, send it. Questions that this page does not answer should go to legal@rndbi.com.
| Cloud provider | Microsoft Azure |
| Region | West US 2 (United States) - single region, no secondary |
| Database | Azure Database for PostgreSQL Flexible Server |
| Application | Container-hosted API behind a static web front end |
| Authentication | Microsoft Entra ID sign-in; no locally-stored passwords |
Sub-processors. Microsoft Azure is the only third party that processes Customer Data. The current list is maintained in our Privacy Policy, section 3, and we will provide notice before adding another.
Record integrity. Trust-accounting controls are enforced in the database rather than in application code. Posted trust transactions cannot be edited or deleted once recorded, by a database-level constraint rather than a UI restriction. This is a recordkeeping-integrity control; it is not a representation that use of the Service satisfies any bar's trust accounting rules. See Terms of Service, section 6.
We would rather publish an unflattering, accurate reliability picture than an uptime number we cannot back.
Separation between firms is currently maintained by controlled provisioning rather than by a boundary the system itself enforces. Access grants are scoped at the project level and issued one firm at a time by the administrator. A system-enforced client-organization boundary is under active development and is the largest single item on our engineering roadmap. Firms whose data-handling requirements depend on a system-enforced boundary rather than an operational one should wait for that work to ship before onboarding.
If we become aware of a security incident that results in unauthorized access to, or acquisition of, Customer Data, we will notify affected Customers without undue delay and in any event as required by applicable law, with the information reasonably available to us about the nature of the incident, the data involved, and the steps being taken. We will cooperate with your own regulatory or client-notification obligations. This commitment is stated in Privacy Policy, section 7.
A formal, documented incident-response runbook with named roles and escalation paths does not yet exist. It is being written.
Stated once, in one place, so nobody has to infer it:
Security questions, vendor due-diligence questionnaires, and vulnerability reports: legal@rndbi.com
We will acknowledge a good-faith vulnerability report and will not pursue legal action against a researcher who reports one to us privately and gives us reasonable time to remediate before disclosure.
This page describes the Service as of the date above and will be revised as the items in section 6 are addressed.