Legal
Security Statement
Effective September 6, 2026
Ressura, Inc. builds software that handles sensitive financial data, so security is foundational to the product. This statement summarizes how we protect your data. It is a summary, not a contract; our binding commitments are in our Terms of Service and Data Processing Agreement.
Hosting and infrastructure
The Service runs on reputable cloud infrastructure providers with strong physical and network security and industry certifications. Production systems are isolated from development and corporate environments.
Encryption
Data is encrypted in transit (TLS) and at rest (AES-256 or equivalent). Secrets and keys are managed through the cloud provider's key-management services.
Access controls
We follow least-privilege principles. Access to production systems and customer data is limited to personnel who need it, requires strong authentication including multi-factor authentication, and is logged and reviewed. Customer-facing single sign-on (SSO) and role-based access are on our roadmap.
Data segregation
Customer Data is logically segregated by account so that one customer cannot access another's data.
AI processing
We use AI to analyze the content you submit. We do not use Customer Data to train our own or any third party's AI models, and our AI subprocessors are contractually bound to the same restriction and to appropriate confidentiality and security controls.
Subprocessors and vendor management
We use a limited set of vetted subprocessors (hosting, payment processing, AI analysis, communications, and monitoring), each bound by contract to confidentiality and security obligations. We maintain a current subprocessor list and notify customers of material changes as described in the DPA.
Backups and resilience
We maintain regular backups and design for recovery of the Service and customer data in the event of a failure.
Secure development and vulnerability management
Security is part of our development process, including code review and dependency monitoring. We track and remediate vulnerabilities on a risk-prioritized basis and intend to conduct periodic third-party security testing as the company scales.
Monitoring and logging
We log access and key events across production systems and monitor for anomalous activity.
Incident response
We maintain an incident-response process and will notify affected customers of a confirmed personal-data breach without undue delay, consistent with the DPA and applicable law.
Compliance roadmap
We are building Ressura to meet the assurance standards our customers rely on. We are working toward SOC 2 (Type II); we are not yet certified, and this statement does not claim any certification we do not hold. A SOC 1 report may follow as customers rely on Ressura within their own financial-reporting controls. We will update this statement as our program matures.
Reporting a concern
Report a suspected vulnerability or security issue to security@ressura.com. We investigate every report and will acknowledge receipt.