Security

Security & Trust

Current preview-stage security information for Ruvix.

Current preview posture

Updated 2026-05-01

Transport security

The website and app are intended to be served over HTTPS/TLS. Plain HTTP should redirect to HTTPS in production.

Tenant separation

Ruvix is designed around workspace/tenant boundaries, with data access scoped to authenticated users and their workspaces.

Secrets handling

Connection credentials and secrets should be encrypted where implemented and must not be logged intentionally.

Operational access

Operational access should follow least-privilege principles and be limited to what is needed to run, troubleshoot, and secure the preview.

Backups and logs

Backups and logs are used for recovery, debugging, abuse prevention, and incident investigation with limited retention.

Data and providers

Primary hosting
Hetzner - EU hosting and infrastructure
Database infrastructure
Hetzner - managed or self-operated database infrastructure & NeonDB
Email
Resend - transactional email
Diagnostics
NewRelic - error monitoring and diagnostics
Data sharing
No personal data is sold or shared for third-party advertising.

Planned improvements

  • Formal security policy and responsible disclosure process
  • Documented backup restore testing cadence
  • External penetration test before broader public availability
  • Formal security controls suitable for broader business use
  • Expanded audit logging and user-visible account security events

Preview limitations

Reporting a vulnerability

Found a security issue? Email security@ruvix.io. Please include enough detail to reproduce the issue. Ruvix aims to respond within two business days.

Ready when you are

Want to try the live preview?

Join the waitlist and we will invite new users in small batches while the preview matures.