Trust & security

What we do with your data, and what we do not have.

This page is written to be checked. Where there is a number, it is the number the platform enforces. The last section lists what we are missing, because you would find it out in the first procurement call anyway.

Analysis

Your submissions stay with us.

Nothing is submitted to a public service

Files and indicators you send us are analysed on hardware we own inside the EU. We do not forward them to a multi-engine scanning service, a public sandbox, or a public URL scanner.

This is worth stating plainly because the industry default runs the other way: on the free tier of most online analysis services, submissions are public or shared with a community, and keeping them private is a paid or enterprise option. We do not sell privacy as an upgrade. No plan we offer submits your data anywhere.

One database file per customer

Findings are stored in a separate database file for each subscriber. There is no shared table with a customer column to filter on, and no per-customer flag that a query can forget.

The practical consequence: an erasure request under Article 17 is the deletion of a file, which can be shown to have happened.

Two-factor is available, not required

Accounts support TOTP two-factor authentication and you can enable it today. We do not enforce it, and the account API reports it as optional.

So if your own policy is that every account at every supplier has it on, that remains your check to make. "Multi-factor authentication" on a security page usually reads as a control the vendor applies. Here it is one you apply.

Responsible disclosure

Found a security issue in our platform? Email support@radecti.com with [SECURITY] in the subject.

We do not run a bug bounty and cannot pay for reports. We will reply.

Retention

A number of days, published per plan.

How long an analysis is kept is a property of your plan and it is written down.

These figures are read from the same catalogue the pricing page uses, and a build check compares them against the code that does the deleting. The page and the platform cannot quietly drift apart.

When the window closes the scan record is deleted: the report, the verdict and the structural detail extracted from the file. A plan whose tier we cannot recognise is skipped and logged instead of swept, because deleting on a bad plan string is not reversible.

Swipe the table sideways to see every column.

How long an analysis is retained on each RADECTI plan
Plan Analysis kept Status
Researcher 7 days Available
Analyst 14 days Available
Analyst Pro 30 days Available
Brand Watch 90 days Available
Surface 180 days Coming soon
Estate 365 days Coming soon

The third-party providers we rely on, what each does and where it operates, are listed in our Terms of Service and maintained in our Privacy Policy. If your supplier review needs more detail on what any one of them holds, ask us and we will answer it directly.

What we do not have

Three things we are missing.

You would establish all of this in the first call. Reading it here first is the reason to believe the rest of the page.

No SOC 2, no ISO 27001

We hold neither certification and we are not mid-audit for either. If your procurement process requires one before you can sign, we do not clear it today.

No 24/7 security desk

Nobody is staffing a console overnight. Automated detection runs continuously; a human reading it does not. A message sent at 3am is read when we are back at a desk.

Best-effort response, not an SLA

RADECTI is a small operation. Security reports reach the people who built the platform directly, which is why they get answered quickly. It is a description of how we work today. There is no contractual response time behind it.