Trust Center

Rumbleo

Trust Center for customers, IT, and compliance

A single entry point for reviewing how Rumbleo approaches privacy, security, providers, data processing, and compliance assessments

Last updated: May 4, 2026

This page summarizes public controls and documents. Signed agreements, security annexes, and customer-specific terms prevail over this public information where they differ

Review by document

Select a compliance document

Each tab is a complete document inside the Trust Center. Privacy Policy and Terms of Use also have their own Trust Center URLs

Security overview

Rumbleo security, architecture, and controls

Document last updated: May 4, 2026

A clear summary of Rumbleo architecture, technical controls, and current limits for B2B security reviews

This summary describes Rumbleo public design and controls as of the date shown. It does not replace contractual annexes or independent audits

01

Executive summary

1.1Rumbleo is designed so organizations can query internal data in natural language without giving AI providers or end users direct access to analytical databases

1.2Every request respects the company, the user, and their permissions. The agent can investigate, but it never receives credentials or decides which data it may access

02

How responsibilities are separated

  1. 2.1The public application does not contain analytical database credentials
  2. 2.2Internal services check identity, permissions, and limits before querying data
  3. 2.3Access from ChatGPT, Claude, Codex, or other compatible assistants is optional and keeps the same permissions
  4. 2.4Data and files are stored with restricted access and encryption

03

Identity, authentication, and roles

  1. 3.1Managed authentication with users invited by authorized administrators
  2. 3.2Password policy with minimum 12 characters and uppercase, lowercase, digit, and symbol requirements
  3. 3.3Sessions have limited validity and a defined expiry
  4. 3.4Separate roles for users, company administrators, and authorized operators
  5. 3.5Company, user, and role come from sign-in rather than values sent by the browser

04

Company separation

  1. 4.1Every customer organization works in a separate space
  2. 4.2Data, agents, users, limits, history, and settings belong to one company
  3. 4.3Every access checks authentication, permissions, and role before showing information or running an action
  4. 4.4One company cannot query another company's data
  5. 4.5Company administrators see aggregate usage statistics, not another person's private conversations or answers

05

Analytical data access

  1. 5.1Customer analytical databases are queried in read-only mode
  2. 5.2External assistants do not receive credentials or open direct connections
  3. 5.3Every query is checked before it runs and write operations are blocked
  4. 5.4Rumbleo applies volume, time, and usage limits for each company
  5. 5.5Technical query details are not shown to end users, although they may be retained for authorized internal review

06

Encryption and secrets

  1. 6.1Public traffic uses HTTPS
  2. 6.2Files are stored encrypted and without direct public access
  3. 6.3Analytical credentials are encrypted and only authorized services can use them
  4. 6.4AI provider keys, when configured, are not exposed in the browser

07

AI, prompts, and model providers

  1. 7.1Rumbleo does not share conversations, results, attachments, semantic models, or customer data with AI providers for model training
  2. 7.2Rumbleo may use OpenAI for conversational functionality when a key is configured, under API/business terms with no training by default unless explicitly opted in
  3. 7.3Some companies may provide their own OpenAI key and retain their contractual relationship with the provider
  4. 7.4Assistants connected through MCP request data from Rumbleo without receiving analytical credentials
  5. 7.5Credentials, connection strings, direct analytical database access, and internal permissions are never given to the AI provider
  6. 7.6Instructions, questions, results, and attachments are treated as customer confidential information and limited to what each feature needs
  7. 7.7The product is designed to ask clarifying questions when context is missing or ambiguous instead of inventing business decisions

08

Records and monitoring

  1. 8.1The platform records functional and technical events needed to operate, protect, and improve the service
  2. 8.2Records may include who made the request, which agent was used, status, duration, usage, and errors needed to investigate incidents
  3. 8.3Calls from connected assistants are also recorded so limits can be applied and failures investigated
  4. 8.4Access to complete records is reserved for authorized staff working on support, security, and quality

09

Data boundary and minimization

  1. 9.1Identity, credentials, business definitions, results, and files are kept separate according to their purpose
  2. 9.2Credentials and connection parameters are not sent to the browser or AI providers
  3. 9.3Business definitions are treated as confidential company information
  4. 9.4Results respect permissions and volume and time limits
  5. 9.5When an AI provider is used, secrets and information not needed for the answer are not sent

10

Application security

  1. 10.1The application checks user, company, and role from the session before running actions
  2. 10.2Administrative operations require specific permissions and are recorded
  3. 10.3Queries are validated as read-only before reaching connected sources
  4. 10.4Error messages do not expose credentials, internal queries, or sensitive system details

11

Internal access and operations

  1. 11.1Internal access to full audit data is reserved to authorized personnel and only for support, security, quality, error investigation, or contractual compliance
  2. 11.2Company administrators may see usage and aggregate statistics, but not another user's private conversations or answers
  3. 11.3Secrets are managed in dedicated services and are not stored in code or operational logs
  4. 11.4The public application, internal services, and external connections have separate permissions

12

Vulnerability management and evidence

  1. 12.1Rumbleo maintains automated tests for company separation, read-only access, permissions, and usage controls
  2. 12.2Changes affecting authentication, permissions, data access, or storage require review and testing proportionate to risk
  3. 12.3Dependencies, images, and third-party services should be reviewed when relevant updates or security advisories apply
  4. 12.4Additional evidence can be prepared for customer audits, including control screenshots, test results, or questionnaire responses
  5. 12.5Formal certifications will only be claimed when a current certificate exists or an independent audit has been completed

13

Backups, continuity, and restoration

  1. 13.1Production files use versioning in the standard configuration
  2. 13.2Retention and restoration are agreed according to the environment and customer requirements
  3. 13.3Backup, restoration, and periodic testing procedures form part of the operational review before handling critical data

14

Change management

  1. 14.1Infrastructure and application changes are reviewed, versioned, and deployed through automated processes
  2. 14.2Database updates preserve a verifiable history
  3. 14.3Integration tests cover company separation, read-only access, permissions, and usage

15

Security improvements under evaluation

  1. 15.1Additional protection for public traffic
  2. 15.2Alerts for availability, errors, and resource usage
  3. 15.3Formal backup and restoration procedures with periodic testing
  4. 15.4Rotation of platform credentials, AI provider keys, and session secrets
  5. 15.5Review of residency, retention, and deletion by data type
  6. 15.6Formal SOC 2, ISO 27001, or Vanta evaluation when customer volume justifies it

Need this for a security review?

Contact info@salatechconsulting.com for vendor questionnaires, additional evidence, or contract annexes

Request a demo