Organization boundaries
Users should see records only for organizations they are authorized to access. Membership and role checks are applied at the workspace level.

RURALREADY TRUST CENTER
RuralReady combines industry-standard encryption, recovery protections, organization-separated access and practical exports to protect the records your team depends on.
Users should see records only for organizations they are authorized to access. Membership and role checks are applied at the workspace level.
Owners and leaders assign roles appropriate to the work. Chief, officer, member, manager and staff access should not be treated as interchangeable.
RuralReady is served over HTTPS/TLS so supported browsers encrypt information while it travels between the device and the service.
Structured customer records are protected with AES-256 encryption at rest through RuralReady’s managed database infrastructure.
Managed point-in-time recovery provides restore points for the database. Recovery availability and retention depend on the hosting service and active plan.
Approved photo and video uploads are organization-scoped and stored in encrypted, redundantly distributed object storage. Redundancy is not a substitute for every customer retention obligation.
Your subscribing organization retains ownership of the records and files it submits. RuralReady receives only the limited rights needed to provide and secure the service.
Supported reports and exports help organizations keep usable copies of their operational and financial history outside the dashboard.
The public marketing site is separate from the operational workspace. Access to private records requires an authorized account and session.
Offline data can remain accessible to anyone who controls an unlocked device. Organizations must use device locks and remove lost-device access promptly.
Customers can use any email address they own or are authorized to control. The organization email comes from the secure sign-in session.
Suspected unauthorized access, lost devices or exposed credentials should be reported immediately so the organization and RuralReady can respond.
New and replacement passwords are checked through a padded, privacy-preserving hash-range request. Known compromised passwords are rejected before account creation or update.
RuralReady’s hosting platform encrypts structured database records at rest using AES-256-GCM and protects database traffic with TLS. Its point-in-time recovery capability supplies recoverable database states rather than relying only on occasional manual copies. Uploaded files are encrypted in storage and redundantly distributed within the storage region.
These safeguards reduce risk, but they do not guarantee that data can never be lost. Organizations with statutory, insurance, grant or records-retention obligations should also download supported reports and maintain any independent copies required by their policy.
Your organization owns its Customer Data. RuralReady uses it only as needed to host, process, protect, back up, display and support the service. Authorized organizations can use supported exports and may request account closure and deletion, subject to legal, security, fraud-prevention and financial-record retention requirements described in the Privacy Policy and Terms.
RuralReady uses infrastructure from providers that maintain recognized security and compliance programs, but a provider’s certification does not automatically certify RuralReady. RuralReady is not currently represented as independently SOC 2, ISO 27001, CJIS, HIPAA or PCI DSS certified. Fire organizations must not use the Service to store criminal-justice information, protected health information, patient-care records or payment-card data. The platform is an operations and readiness tool, not an ePCR or law-enforcement records system.
Email h-vclients@outlook.com with “RuralReady security report” in the subject. Do not include passwords or sensitive record contents in the email.