Security and compliance
What protects your account today, what we are working toward, and what we will not claim until it is true.
These documents describe how rctuners actually works, but they have not yet been reviewed by a lawyer. They will be before the site opens.
Where we stand
rctuners is not SOC 2 or ISO 27001 certified. Those are certifications of an organisation's controls operating over time, awarded after an external audit; a site cannot simply declare itself certified, and we will not. What we can say is that the site is built to those control sets from the start — so that when the audit comes, it is an audit and not a rebuild.
We intend to pursue SOC 2 Type II on the Security, Confidentiality and Privacy criteria first, and ISO/IEC 27001 after it. The timing follows our members and partners: the observation window opens when the first business customer needs the report. This page will change the day either is in hand, and not before.
What is built today
In transit: everything is served over TLS, with HSTS so a browser never falls back to plain HTTP.
Passwords are stored as salted hashes, never in a form we or anyone else could read back. A reset link is single-use and expires.
Sessions are yours to end: sign out everywhere else from settings, and changing your password does it for you.
An audit log records every sign-in, failed attempt, password change, consent, export, deletion and administrative action — who, what, from where, when. It is append-only in the database and hash-chained, so an altered or removed entry breaks the chain from that point on. It is kept for 12 months.
You can read your own trail on your account settings page: sign-ins with device and address, failed attempts on your name, and every change to the account. A sign-in you do not recognise is the earliest warning there is, and it goes to the one person who can act on it.
Uploads are checked for malware before they are stored, and every image has its metadata — including GPS coordinates — stripped.
No payment data exists here by design. Deals between members are settled between members.
What we do not collect: your real name, phone number, precise location or date of birth (we keep only whether you were 16).
Your rights, self-serve
Export everything you have given us as a machine-readable file, or delete your account, from your privacy settings — without asking us. Deletion removes your media and profile at once and tombstones your messages so the conversations you were in still make sense to the others in them. Backups clear on their rotation.
The Privacy Policy sets out every category of data, why it is held and for how long.
What is still ahead
Written down so that this page cannot quietly overstate things: encrypted backups with a tested restore; the audit log's chain head published off the machine, so that tampering with our copy cannot go unnoticed; a written incident-response plan with a 72-hour notification path; an independent penetration test before any certification attempt. Each moves from this list to the one above when it is done.
Reporting a vulnerability
If you find a security problem, tell us at legal@rctuners.com before telling anyone else. We will acknowledge within two working days, keep you informed, and will not take action against good-faith research that stays within your own accounts and data.