Security & Trust

Security and Data Practices

When we build your AI agents and platforms, we touch real systems and real data. Here’s exactly how we protect them — the questions a security-literate buyer asks, answered before you have to ask them.

  • Encrypted in transit & at rest, least-privilege access
  • Your data is never used to train AI models
  • We sign your NDA & DPA
Senior team onlyNo juniors, no offshore pass-throughs
Security and trust at REO Rank
TLS 1.2+
encrypted end-to-end
No model training
on your data

Your data

How we handle it.

The controls that apply to every engagement, from a one-page audit to a full platform build.

Encryption everywhere

Data encrypted in transit (TLS 1.2+) and at rest. No client data on personal devices — ever.

Least-privilege access

Role-based access, SSO where you have it, and access granted per-engagement — then revoked when it ends.

Data residency

We can keep data in your region and your cloud boundary when a project requires it. Tell us the constraint.

Retention & deletion

We hold only what the work needs, for as long as it needs it, and delete on request or at engagement end.

NDAs & DPAs

We sign your NDA and Data Processing Agreement. If you don’t have one, we bring a sensible template.

Vetted, senior team

No offshore juniors touching your systems. The people with access are the senior specialists on your account.

AI & your data

The questions technical buyers actually ask.

Building AI agents means being straight about models, data and guardrails.

You choose the model

Provider-agnostic. We can run on providers with zero-retention / no-training terms, or open models in your own boundary.

No training on your data

Client data is never used to train models. We use providers’ enterprise tiers where inputs are excluded from training.

PII redaction & guardrails

Input/output guardrails, PII detection and jailbreak checks sit around every agent before it reaches a customer.

Typed, auditable tool access

Agents reach your systems through typed MCP tools with scoped permissions and full request tracing — not raw keys.

Infrastructure & practices

How we build and run it.

Anything we ship or operate for you is built the way production software should be.

Infrastructure as code

Reviewable, repeatable infra — no one-off console clicks that no one can audit later.

Monitoring & alerting

Logs, metrics and traces with alerts, so issues are caught before your users feel them.

Backups & recovery

Automated backups with tested restore paths and documented RTO/RPO for anything we run for you.

Dependency & secret scanning

Automated scanning for vulnerable dependencies and leaked secrets in every pipeline.

Secure SDLC

Code review, protected branches and CI gates — changes are reviewed and reversible, not YOLO’d to prod.

Incident response

A documented plan for when something goes wrong: contain, communicate, fix, and write it up honestly.

Compliance

Where we stand.

We operate to recognised controls; formal attestations are shared under NDA — ask for the current picture.

SOC 2 controls

Operated; attestation status under NDA.

GDPR & CCPA

DPAs, data-subject requests, residency options.

HIPAA-aware

For healthcare work — BAAs and safeguards on request.

NDAs & DPAs

Signed fast; templates provided if you need them.

Security questions

Straight answers

What procurement and security teams check first.

Will you sign our NDA and DPA?
Yes — send them over and we will turn them around quickly. If you do not have a Data Processing Agreement, we can provide a standard template to start from.
Do you use our data to train AI models?
Never. Client data is not used to train any model. For AI work we use enterprise tiers where your inputs and outputs are excluded from training by the provider, or we run open models inside your own environment entirely.
Where is our data stored?
By default in our standard cloud region. When data residency matters — regulated industries, contractual constraints — we can deploy into your cloud account and region so data never leaves your boundary.
Who on your team can access our systems?
Only the senior specialists actively working on your account. Access is granted per-engagement, scoped to the minimum required, and revoked when the engagement ends. No shared logins, no juniors, no offshore contractors.
How do you control access to client accounts?
Role-based access with the principle of least privilege. We use SSO where you have it, and we request scoped read/write permissions rather than admin keys. Every access grant is documented and revoked at engagement end — we do not keep keys sitting in a shared inbox.
What encryption do you use?
TLS 1.2 or higher for everything in transit. Data at rest is encrypted in the cloud storage layer. No client data lives on personal devices.
Are you SOC 2 or ISO 27001 certified?
We operate to those controls — encryption, access management, monitoring, incident response, and secure SDLC. Formal certification status and current attestations are shared under NDA. Ask and we will give you the honest, current picture.
What is your incident response process?
We have a documented plan: contain the issue, notify affected parties promptly, fix the root cause, and write it up honestly. If something goes wrong that affects your systems or data, you hear from us first — not after we have already cleaned it up quietly.
How do you handle PII and sensitive data in AI agents?
Input and output guardrails sit around every agent we build. PII detection runs before data reaches a model. Jailbreak checks and output filters are layered on top. Agents reach your systems through typed, auditable tool calls with scoped permissions — not raw API keys or open database connections.
How do we report a security concern?
Email hello@reorank.com with "Security" in the subject line and we will acknowledge it quickly and work through it with you. Responsible disclosure is welcome — we do not penalise people for finding and reporting issues.

Still have questions? Talk to a specialist

Company

More about REO Rank.

How we work, who does the work, and how to start a conversation.

Who we are and how a senior-led team actually runs an engagement.

Our engagement model, week by week — from audit to shipped results.

The senior operators who do the work on your account — no juniors.

Open roles for senior specialists who want ownership, not tickets.

Transparent, KPI-tied engagement pricing with no lock-in.

Tell us what you are trying to fix — we will be honest about fit.