Security & Compliance at RecMan

RecMan is built to meet the security, privacy, and reliability expectations of customers. This article is a starting point – each section below links to a more detailed article.

Quick links

Security

RecMan's infrastructure runs entirely within the EU/EEA on AWS, with encryption in transit (TLS) and at rest (AES-256), multi-factor authentication and SSO, continuous security monitoring, and a structured vulnerability management program including regular penetration testing. For more information, see Information Security Practices.

Certifications and Compliance

RecMan is ISO/IEC 27001:2023 certified and has completed a SOC 2 Type I report. We are GDPR-compliant by design, with our infrastructure and default data processing located within the EU/EEA. For more information, see Certifications & Compliance Frameworks.

Availability, Backup & Disaster Recovery

RecMan is deployed across multiple availability zones within the EU/EEA, with auto-scaling and DDoS protection to maintain service continuity. Regular, redundant backups with tested restoration procedures, supported by a documented Business Continuity and Disaster Recovery (BCDR) plan. For more information, see Availability, Backup & Disaster Recovery.

Data Privacy and Retention

Customer data is retained only as long as necessary and is automatically and permanently deleted within 14 days of subscription termination. For more information, see Data Privacy & Retention.

Need something not covered here?

For anything potentially requiring an NDA (full SOC 2 report including control descriptions, Statement of Applicability, penetration test summaries), contact our customer service at support@recman.io.

Was this article helpful?
0 out of 0 found this helpful