Trust · Security
RedeApp's security architecture is purpose-built for the frontline reality: unmanaged devices, mixed labor models, regulated industries. SOC 2 Type II controls map cleanly to standard enterprise security frameworks; the agentic governance layer extends those controls into AI decision-making.
Procurement-grade trust documentation has a specific shape: clear architecture, explicit controls, named auditors, public sub-processors, and signed agreements. This page covers security architecture.
The four dimensions
Each row below names a dimension and what RedeApp publishes about it.
256-bit AES encryption at rest including backups and system media. TLS 1.2+ enforced in transit (audit control CC6.6.3). Customer-managed KMS keys via AWS KMS. Per-customer encryption boundaries with VPC isolation available. Production cloud access restricted to private virtual networks via Pritunl/OpenVPN under principle of least privilege.
Native integration with enterprise IdPs: Microsoft Entra ID, Okta, Ping Identity, Google Workspace — via SAML 2.0 and OIDC. MFA enforced for administrative access (audit control CC6.1.3): 14-character minimum passwords, complexity rules, 90-day rotation. SCIM 2.0 just-in-time provisioning. RedeKey reconciles frontline identity sources (badge, clock-in, contractor records).
Automated HRIS synchronization via secure SFTP. Endpoint: ssh.redeapp.com (port 22, SSH public-key authentication, asymmetric cryptography via OpenSSH). TSV preferred format. Termination flag in HRIS feed triggers automated user deprovisioning + remote device wipe — erasing corporate messages, file repositories, and cache from the employee's mobile device.
Compliance-grade activity logging via Scout. SOC 2 Type II audit-ready event stream. Customer-controlled retention and export. Annual external third-party penetration tests on web and mobile applications (CC4.1.1). Breach notification SLA: any verified data breach reported without unreasonable delay, with a 10-calendar-day legal notification window per Master Services Agreement and BAA.
Next step
Your security review committee can reach our enterprise team for any clarification or specific controls inquiry.