Next open exercise: date TBA.Notify me
TRUST · v1.1·EARLY ACCESS · HONEST POSTURE

Trust at ReadTheRoom.

We're early access. This page is the honest version of our security posture: what we have today, who we partner with for infrastructure, what we don't have yet, and what's on the roadmap. Everything below is true at the date this page was last updated.

LAST UPDATED · 2026-05-25 · OWNED BY FOUNDER

01 / WHERE YOUR DATA LIVES·Hosted on SOC 2 Type II infrastructure

Your scenario data never leaves audited infrastructure.

ReadTheRoom runs on three vendors, each independently audited for security. We don't operate our own data centers. Your data lives entirely on infrastructure that has been formally certified.

Cloud Application Platform
VENDOR · 01
Application hosting, managed database, file storage, and global edge network
✓ SOC 2 Type II✓ ISO 27001✓ GDPR✓ HIPAA-ready
Real-Time Infrastructure
VENDOR · 02
Low-latency WebSocket servers powering live simulation events
✓ SOC 2 Type II
Frontier AI Provider
VENDOR · 03
Large language models powering the AI Co-designer, Inject Advisor, and Bot Players
✓ SOC 2 Type II✓ GDPR✓ Zero data retention
02 / HOW WE PROTECT IT·Engineering posture today

What's actually true about our security.

These are practices we've implemented and can demonstrate today. Not roadmap items, not aspirations.

  • [✓]Encrypted in transit (TLS 1.3) on every connection
  • [✓]Encrypted at rest (managed by our cloud platform and database providers)
  • [✓]Role-based access controls: every action attributed and audit-logged
  • [✓]Every decision, inject, deliverable, and export is timestamped and exportable
  • [✓]Participant consent before any data is used for research; IRB-aligned (training-only runs collect none)
  • [✓]Daily automated backups (managed by infrastructure providers)
  • [✓]Two-factor authentication required on all admin and operator accounts
  • [✓]Principle of least privilege for internal access (founder-only today)
  • [✓]No customer data is used to train AI models; our AI provider operates with zero data retention
03 / CERTIFICATIONS·Where we stand

You'll get a straight answer.

We do not hold SOC 2, ISO 27001 or FedRAMP. You should hear that here rather than find it at contract stage. Certification follows what our clients' security reviews actually require, and we scope it against your timeline rather than publishing dates we have not committed to.

SIGN-READY TODAY
Data Processing Agreement

Available on request and ready to sign, covering the controls described above.

ASK US EARLY
Whatever your security review needs

Send us the questionnaire. We will tell you what we meet today, what we would have to build, and how long it would take. If we cannot meet your requirement, we will say so.

04 / QUESTIONS·Talk to the founder

Security questions get a same-day answer.

Procurement requirements, DPA review, specific compliance questions, or vendor-due-diligence packages. Request a demo and the founder will respond directly within 24 hours.

TRUST · CONTACT
Request a Demo
We'll connect you with the founder for any security or procurement question.
Book a Demo →

This page reflects our security posture as of 2026-05-25. We update it when the underlying reality changes. If you find something here that doesn't match what we tell you on a call, the call is wrong, not the page.