SIG RQMS-SEC-005·REV 06·Live

Your lab's data.
Your lab's alone.

RainerQMS is built on strict tenant separation: your quality records are isolated from every other customer's at every layer of the platform. This page is the plain-language tour of the controls — what we commit to, and how to hold us to it.

CH·01·THE CONTROLS

Defense, itemized.

No fog, no theater — what the platform commits to, in plain language.

Strict tenant separation

Your quality records are isolated from every other customer's at every layer of the platform. Separation is a property of the architecture — not a setting someone could forget to apply.

Encryption

TLS for every connection and encryption at rest. Sessions use signed, short-lived tokens with immediate revocation. Dedicated encryption keys per customer on Enterprise.

Access control

Role-based permissions per product, module and action — deny by default. MFA (TOTP), SSO via OIDC, strong password policy and automatic account lockout.

Append-only audit trail

Every create, change, approval and login is recorded with actor, action and time. Writes only. No API exists to edit or delete an audit record. That's the point.

Part 11 e-signatures

Identity re-verified at signing; name, meaning and timestamp bound to a SHA-256 hash of the record. Repudiation is not a feature.

Application security

Strict security headers, schema-validated input on both ends, sanitized rendering, and uploads restricted by allowlist with malware scanning hooks.

Perimeter controls

Every request is authenticated, scoped to your workspace and rate-limited before it can touch a record. Unauthenticated traffic never reaches your data.

Availability

99.9% uptime SLA (99.95% on Enterprise), with recovery objectives of RPO 1 hour / RTO 4 hours — 15 minutes / 1 hour on Enterprise.

Data portability

Your data stays yours. On request — or on exit — you receive a complete export of records, documents, files and the full audit trail, in open formats, at no charge.

0

ways to edit or delete an audit record — no such API exists

100%

of signatures bound to a cryptographic hash of the signed record

99.9%

uptime SLA — 99.95% on Enterprise plans

≤2days

to acknowledge any security report, in writing

CH·02·DATA PROTECTION

GDPR, in writing.

We process your laboratory's data as a processor under a signed Data Processing Agreement, with EU Standard Contractual Clauses for international transfers and a published subprocessor list. Data subject rights are honored on request — access, rectification, erasure, portability.

Read the DPA

CH·03·RESPONSIBLE DISCLOSURE

Found something? Tell us. We'll say thank you — in writing.

Security reports go straight to the engineers who can fix them. We acknowledge within 2 business days, keep you informed, and credit researchers who report in good faith. Our disclosure policy lives at /.well-known/security.txt — where it belongs.

REPORT TO

security@rainerqms.com

PGP key available on request · response within 2 business days

Good-faith safe harbor

DUE DILIGENCE

Send us your security questionnaire.
We answer those for a living.

Security & Trust — strict tenant separation, immutable audit trails · RainerQMS