Questions before you start?Contact RuralReadyOpen RuralReady →

RURALREADY TRUST CENTER

Your operation’s data stays yours.

RuralReady combines industry-standard encryption, recovery protections, organization-separated access and practical exports to protect the records your team depends on.

01

Organization boundaries

Users should see records only for organizations they are authorized to access. Membership and role checks are applied at the workspace level.

02

Role-based access

Owners and leaders assign roles appropriate to the work. Chief, officer, member, manager and staff access should not be treated as interchangeable.

03

Encrypted in transit

RuralReady is served over HTTPS/TLS so supported browsers encrypt information while it travels between the device and the service.

04

Encrypted at rest

Structured customer records are protected with AES-256 encryption at rest through RuralReady’s managed database infrastructure.

05

Database recovery

Managed point-in-time recovery provides restore points for the database. Recovery availability and retention depend on the hosting service and active plan.

06

Protected file storage

Approved photo and video uploads are organization-scoped and stored in encrypted, redundantly distributed object storage. Redundancy is not a substitute for every customer retention obligation.

07

Customer-owned data

Your subscribing organization retains ownership of the records and files it submits. RuralReady receives only the limited rights needed to provide and secure the service.

08

Portable records

Supported reports and exports help organizations keep usable copies of their operational and financial history outside the dashboard.

09

Private operations app

The public marketing site is separate from the operational workspace. Access to private records requires an authorized account and session.

10

Offline awareness

Offline data can remain accessible to anyone who controls an unlocked device. Organizations must use device locks and remove lost-device access promptly.

11

Verified account email

Customers can use any email address they own or are authorized to control. The organization email comes from the secure sign-in session.

12

Security reporting

Suspected unauthorized access, lost devices or exposed credentials should be reported immediately so the organization and RuralReady can respond.

13

Breached-password screening

New and replacement passwords are checked through a padded, privacy-preserving hash-range request. Known compromised passwords are rejected before account creation or update.

Encryption, recovery and backups

RuralReady’s hosting platform encrypts structured database records at rest using AES-256-GCM and protects database traffic with TLS. Its point-in-time recovery capability supplies recoverable database states rather than relying only on occasional manual copies. Uploaded files are encrypted in storage and redundantly distributed within the storage region.

These safeguards reduce risk, but they do not guarantee that data can never be lost. Organizations with statutory, insurance, grant or records-retention obligations should also download supported reports and maintain any independent copies required by their policy.

Your data and your choices

Your organization owns its Customer Data. RuralReady uses it only as needed to host, process, protect, back up, display and support the service. Authorized organizations can use supported exports and may request account closure and deletion, subject to legal, security, fraud-prevention and financial-record retention requirements described in the Privacy Policy and Terms.

What organization leaders must do

  • Invite only people who need access and review the member list regularly.
  • Use a unique password and protect the email account used for recovery.
  • Lock every field device and keep its browser and operating system updated.
  • Remove departed users, shared devices and lost devices without delay.
  • Avoid storing Social Security numbers, complete payment-card data, criminal-justice information or unnecessary medical information.
  • Verify that offline changes have synchronized before treating the central record as current.

Certifications and regulated data

RuralReady uses infrastructure from providers that maintain recognized security and compliance programs, but a provider’s certification does not automatically certify RuralReady. RuralReady is not currently represented as independently SOC 2, ISO 27001, CJIS, HIPAA or PCI DSS certified. Fire organizations must not use the Service to store criminal-justice information, protected health information, patient-care records or payment-card data. The platform is an operations and readiness tool, not an ePCR or law-enforcement records system.

Report a concern

Email h-vclients@outlook.com with “RuralReady security report” in the subject. Do not include passwords or sensitive record contents in the email.