Trust centre
Security you can verify, not just take on trust.
RUBIQ sells governance, so the platform has to model it. This page sets out, in plain language, how we protect the data you share, where our certification stands, and how to report a problem.
How we protect your data
Six commitments, applied to ourselves.
Encrypted in transit and at rest
Traffic to RUBIQ runs over modern TLS, and data is encrypted where it is stored. The connection to this website is HTTPS-only.
Who can see what
Access is role-based and least-privilege: single sign-on, row-level security, and permissions scoped to the job, not the person. People see the records their role needs, and no more.
Every action leaves a record
Activity is logged and monitored continuously. The same audit trail that RUBIQ gives customers over their own governance applies to how the platform is run.
Governed by design
Data is catalogued, classified with sensitivity labels, and tracked through its lineage. Data residency is configurable, and the platform is built to hold the minimum it needs.
When something goes wrong
We keep a documented incident-response process. Where a security compromise affects personal information, we notify the Information Regulator and the people affected, as POPIA section 22 requires.
Kept current
Dependencies are pinned and reviewed, software is patched, and the site ships a strict content-security policy and a hardened set of security headers.
This website
The marketing site holds almost nothing, on purpose.
- No tracking. No cookies and no non-essential device storage, which is why there is no consent banner. See the cookie notice.
- No lead data kept on the site. What you submit is passed to our CRM and email tools over an encrypted connection; the site itself stores no personal information.
- Hardened delivery. HTTPS-only with HSTS, a strict content-security policy, and security headers that block framing and content sniffing.
- Layered form defence. Submissions are validated, rate-limited, and screened for spam before anyone sees them.
How we handle the information you give us, your rights, and how long we keep it, is set out in full in our privacy policy.
Sub-processors
Who else touches your data.
We use a small set of service providers to run the site and follow up on enquiries. Each works under a written agreement that limits them to acting on our instructions. We keep this list current.
| # | Provider | What it does | Region |
|---|---|---|---|
| Vercel, Inc. | Website hosting, delivery, and server logs | United States | |
| CORA (Guideline BizTech) | Recording and following up on enquiries | South Africa | |
| Microsoft 365 (Microsoft Corporation) | Transactional email from forms, and demo bookings | United States and EU | |
| Plausible Analytics | Cookieless traffic measurement | European Union |
- Provider
- Vercel, Inc.
- What it does
- Website hosting, delivery, and server logs
- Region
- United States
- Provider
- CORA (Guideline BizTech)
- What it does
- Recording and following up on enquiries
- Region
- South Africa
- Provider
- Microsoft 365 (Microsoft Corporation)
- What it does
- Transactional email from forms, and demo bookings
- Region
- United States and EU
- Provider
- Plausible Analytics
- What it does
- Cookieless traffic measurement
- Region
- European Union
This list matches the operators named in our privacy policy. If it changes, this page, the privacy policy, and the cookie notice are updated before the change takes effect.
Responsible disclosure
Found a security issue? Tell us.
If you believe you have found a vulnerability in this website or in RUBIQ, please report it to us privately so we can fix it before it is made public. We will acknowledge your report and keep you updated.
Report to
Please do not test against live systems in a way that could affect other people's data or the service. Give us reasonable time to respond before any public disclosure.
Want the detail your security team needs?
We are happy to walk your team through how RUBIQ governs and protects data on a live call.