Platform controls
- Encryption — TLS 1.2+ in transit; AES-256 at rest for database storage and backups.
- Tenant isolation — every customer record is scoped by an organisation identifier and protected by row-level security policies enforced in the database.
- Access control — role-based access with ten built-in roles and 28 granular permissions, plus an immutable audit log of administrative actions.
- Authentication — password and magic-link sign-in, email verification, TOTP-based multi-factor authentication (Google Authenticator, 1Password, Authy and compatible apps), and leaked-password protection backed by the Have I Been Pwned breach corpus.
- SSO roadmap — SAML single sign-on for Enterprise plans is on the roadmap; contact us if it is required for your evaluation.
- Hosting — managed infrastructure in European Union (Frankfurt / Dublin), with backups and tested restore procedures.
- Responsible disclosure — a published security contact, a 2 business-day acknowledgement target, and a vulnerability handling procedure.
Data protection
We act as a data processor for Customer Data and offer a customer-facing Data Processing Agreement aligned with UK GDPR and EU GDPR. Our current sub-processor list is published and versioned.
Reporting a vulnerability
We welcome responsible disclosure. Please email security@react-ims.com with details and steps to reproduce. We will acknowledge within two business days.
Status
Live platform status and incident history: /status.