Trust Centre
Security, privacy and compliance at React-IMS
We build React-IMS for organisations whose compliance posture depends on us. Everything we publish here describes how we operate today — not a future roadmap.
- EU-hosted infrastructure with encryption at rest and in transit
- Tenant isolation enforced by database row-level security
- TOTP multi-factor authentication and leaked-password protection
- Immutable audit log of administrative actions
- Published sub-processor list with 30 days' notice of changes
- Responsible disclosure channel with 2 business-day acknowledgement
Browse the Trust Centre
Each page below is maintained by Tamam Technologies Ltd (trading as React-IMS). None of these documents constitute independent certification; they are the basis for your own due diligence and the contractual commitments we are prepared to make.
Security overview
Encryption, tenant isolation, MFA, leaked-password protection and access controls.
OpenSub-processors
The third parties that help us deliver the service, with locations and safeguards.
OpenPrivacy policy
What we collect, why, how long we keep it, and the rights available to data subjects.
OpenData processing agreement
Article 28 DPA aligned with UK GDPR and EU GDPR, available to every customer.
OpenCookie policy
Essential, functional and analytics cookies, and how the consent banner works.
OpenAcceptable use
What the platform may and may not be used for, and how abuse is handled.
OpenPlatform status
Live system status and recent incidents.
OpenTerms of service
The SaaS subscription terms that govern use of React-IMS.
OpenNeed something specific?
Enterprise customers can request a signed DPA, a vendor security questionnaire response, a sub-processor change subscription, or a security review call.