Rundocs › More
Information Security
Last updated 2026-09-19
The Rundoo Policies page outlines the company's key policies, including information security, data retention, change management, incident management, third-party risk, security awareness, roles, software/hardware management, data classification, access control, and disaster recovery. These policies ensure data protection and operational continuity.
Rundoo Information Security Program Policy
1. Overview
Rundoo maintains a comprehensive Information Security Program (“Program”) designed to protect the confidentiality, integrity, and availability of sensitive information, including customer data, company records, and proprietary information. The Program is aligned with industry standards and applicable legal requirements but is tailored to Rundoo’s specific operational needs and priorities.
2. Scope
This Program applies to all employees, contractors, and third-party service providers of Rundoo who handle sensitive information or access Rundoo’s systems and infrastructure. The guidelines set forth in this policy serve as a framework for ensuring secure operations, but adherence does not constitute any warranty or guarantee of complete security.
3. Key Elements of the Program
- Risk Management: Rundoo conducts periodic risk assessments to identify potential vulnerabilities in its systems and processes. Risk mitigation strategies are implemented based on these assessments but are not exhaustive of all risks.
- Access Controls: Role-based access is enforced to ensure that individuals only access data necessary for their job functions. Access controls are reviewed regularly but are not a guarantee against unauthorized access.
- Data Encryption: Rundoo employs encryption technologies to safeguard sensitive data both at rest and in transit, though encryption does not ensure absolute protection from breaches or unauthorized disclosure.
- Incident Response: Rundoo has an incident response plan in place to address data breaches or security incidents promptly. Response efforts are handled as appropriate to the nature of the event but do not guarantee specific remedies or resolutions.
- Employee Training: All personnel receive training on data security protocols relevant to their roles. Ongoing education is provided, but Rundoo does not warrant that all potential threats will be covered or mitigated.
4. Program Modifications
Rundoo reserves the right to modify or update this Information Security Program at its discretion, without prior notice. Any changes will be made in the interest of protecting Rundoo’s operations and data, and no specific results or security outcomes are guaranteed.
5. Disclaimer
This policy is intended as a general guideline for information security management. It does not create any contractual obligations, representations, or warranties by Rundoo regarding the absolute security of information or systems. The Program is subject to change based on evolving threats, legal requirements, and business needs.
Rundoo Data Record Retention Policy
1. Overview
Rundoo’s Data Record Retention Policy (“Policy”) establishes guidelines for the retention, storage, and disposal of records and data within the company. This Policy is designed to ensure compliance with applicable legal and regulatory requirements while aligning with Rundoo’s operational needs.
2. Scope
This Policy applies to all data and records generated, received, or maintained by Rundoo, including but not limited to customer data, employee records, financial documents, and business communications. The retention periods specified are guidelines and may be adjusted as needed based on legal obligations or business requirements.
3. Retention Periods
- Customer Data: Retained for the duration of the business relationship and for a minimum of one (1) year after the relationship ends, unless otherwise required by law.
- Employee Records: Retained for a minimum of seven (7) years following the termination of employment, in accordance with applicable employment laws and regulations.
- Financial Records: Retained for a minimum of seven (7) years from the date of creation, unless longer retention is required for tax or audit purposes.
- Business Communications: Retained for a minimum of one (1) year unless a longer retention period is required by law or contract.
4. Data Disposal
Once data or records have reached the end of their retention period, they will be securely disposed of using appropriate methods such as data wiping, shredding, or other means that ensure the data cannot be recovered or reconstructed. However, Rundoo makes no guarantees that all deleted data is unrecoverable by third-party forensic methods.
5. Exceptions and Legal Holds
In the event of ongoing litigation, audits, or investigations, relevant data and records may be subject to a legal hold and will be retained until the hold is lifted. Rundoo reserves the right to suspend routine disposal processes as necessary to comply with legal obligations.
6. Program Modifications
Rundoo reserves the right to amend or modify this Policy at any time, without prior notice, to reflect changes in legal requirements or business needs. No specific outcomes or assurances are provided as part of this Policy.
7. Disclaimer
This Policy is provided as a general guideline for record retention. It does not constitute any representation or warranty as to the completeness, security, or continued availability of records. Rundoo disclaims any responsibility for any consequences that may arise from deviations from these guidelines.
Rundoo Change Management Program Policy
1. Overview
The Rundoo Change Management Program (“Program”) outlines the procedures and controls for managing changes to Rundoo’s systems, applications, and infrastructure. The Program is designed to minimize disruption to operations, ensure the integrity of systems, and maintain security while facilitating necessary updates or modifications. This document serves as a guideline and is subject to change at Rundoo’s discretion.
2. Scope
This Program applies to all system changes, including but not limited to software updates, infrastructure modifications, and configuration changes, initiated by Rundoo’s internal teams or external service providers. All changes must be submitted through Rundoo’s technical system, GitHub, and require peer review before implementation. These guidelines aim to ensure effective change management but do not guarantee the prevention of all risks or disruptions.
3. Change Management Process
- Change Requests: All changes must be formally requested through Rundoo’s internal tracking system. Requests will be evaluated based on their potential impact on system performance, security, and business continuity.
- Impact Assessment: Each change will undergo an impact assessment to determine the risks and benefits associated with the modification. Rundoo does not warrant that all risks will be identified or mitigated.
- Peer Review: All changes, regardless of their size or significance, must be submitted through GitHub and undergo a peer review process. Changes are only approved after review and consensus from designated team members, though this process does not guarantee the absence of errors or issues.
- Approval Process: Significant changes must be reviewed and approved by the appropriate stakeholders, including IT and security teams. Emergency changes may bypass this step but will be documented and reviewed post-implementation.
- Testing and Validation: Where feasible, changes will be tested in a controlled environment before being deployed to production systems. Rundoo will make best efforts to ensure smooth deployments but does not guarantee that all issues will be identified in testing.
- Implementation: Approved changes will be implemented according to the designated schedule. Rundoo aims to minimize operational disruptions but cannot ensure that no interruptions or side effects will occur.
- Post-Change Review: After the implementation of significant changes, a review will be conducted to evaluate the success of the change and any lessons learned. This review does not provide assurances of future performance or risk prevention.
4. Emergency Changes
Emergency changes necessary to address critical vulnerabilities or operational failures may be implemented immediately without full adherence to the standard approval process. Rundoo will prioritize restoring operations but does not guarantee the prevention of adverse effects in such cases.
5. Program Modifications
Rundoo reserves the right to modify or update this Program at any time without notice, based on evolving operational needs or regulatory requirements. No specific security or operational performance guarantees are implied.
6. Disclaimer
This Change Management Program is intended as a general framework for managing changes within Rundoo’s systems. It does not create any contractual rights or obligations, nor does it guarantee specific results, system uptime, or security outcomes. Rundoo disclaims any liability for disruptions or issues arising from changes made under this Program.
Rundoo Incident Management Program Policy
1. Overview
The Rundoo Incident Management Program (“Program”) provides guidelines for identifying, managing, and resolving security and operational incidents that may impact Rundoo’s systems, data, or services. This Program is designed to ensure prompt and efficient responses to incidents, minimizing potential risks and operational downtime. These guidelines are subject to change at Rundoo’s discretion and do not guarantee specific outcomes.
2. Scope
This Program applies to all security and operational incidents affecting Rundoo’s systems, including but not limited to system outages, data breaches, and performance issues. The procedures outlined below ensure that incidents are managed appropriately but do not cover every possible situation or incident type.
3. Incident Management Process
- Detection and Notification: Rundoo uses PagerDuty to monitor system health and detect incidents. When an incident is detected, PagerDuty automatically alerts the on-call engineer via phone call, email, text message, and SMS. Notifications are configured to override any silence settings on the engineer’s devices, ensuring prompt awareness of the incident.
- Escalation: Rundoo maintains a 24/7 on-call schedule with engineers rotating to provide continuous coverage. If the on-call engineer fails to respond within a defined timeframe, the incident automatically escalates to other team members to ensure timely response and resolution.
- Assessment: Once notified, the engineer assesses the nature and scope of the incident. Immediate containment actions are taken to mitigate potential damage or data loss, while further investigation determines the root cause.
- Resolution: Rundoo leverages GitHub version control to facilitate rapid recovery from system issues. In the event of a malfunction caused by a recent system change, engineers can easily roll back to a previous commit to restore stable system functionality. This rollback capability minimizes downtime and ensures that the integrity of the system is preserved.
- Post-Incident Review: After an incident has been resolved, a post-incident review is conducted to analyze the cause, assess the response, and identify any areas for improvement. This review does not guarantee the prevention of future incidents but informs ongoing security and operational improvements.
4. Communication
Rundoo is committed to transparency during significant incidents. If an incident affects customers or partners, Rundoo will provide timely updates to stakeholders on the status of the incident and any actions taken. However, no specific commitments are made regarding the timing or frequency of these updates.
5. Program Modifications
Rundoo reserves the right to modify or update this Program at any time, without prior notice, based on evolving security threats, operational needs, or legal requirements. This flexibility allows Rundoo to remain agile in its response to incidents, though no specific outcomes are guaranteed.
6. Disclaimer
This Program is intended as a general framework for managing incidents and does not create any contractual rights or obligations. Rundoo disclaims any liability for specific incidents or damages resulting from incidents. While every effort will be made to respond promptly and effectively, this Program provides no guarantees of system uptime, data protection, or security outcomes.
Rundoo Third-Party Risk Management Program Policy
1. Overview
The Rundoo Third-Party Risk Management Program (“Program”) outlines the procedures for assessing and managing the risks associated with third-party vendors that provide critical services to Rundoo. This Program ensures that third-party service providers are vetted and monitored to mitigate potential security, operational, and financial risks. These guidelines are subject to change at Rundoo’s discretion and do not guarantee specific risk mitigation outcomes.
2. Scope
This Program applies to all third-party vendors and service providers with access to or involvement in Rundoo’s operations, systems, or data. Specifically, Rundoo relies on the following key third-party providers:
- Google Cloud Platform (GCP): Rundoo’s infrastructure is hosted on GCP, including servers, databases, and storage. GCP provides secure, scalable infrastructure, and Rundoo leverages GCP’s built-in security features to safeguard our operations.
- Stytch: Rundoo uses Stytch for user authentication, ensuring secure and reliable access control for our systems.
- Stripe: Rundoo processes payments through Stripe, relying on their robust payment security features for handling sensitive financial transactions.
3. Vendor Risk Assessment
- Initial Evaluation: Before engaging any third-party service provider, Rundoo conducts a thorough risk assessment. This includes evaluating the provider’s security protocols, regulatory compliance, and financial stability. Specific attention is paid to data security, uptime guarantees, and incident response capabilities.
- Ongoing Monitoring: Rundoo conducts periodic reviews of third-party vendors to ensure they continue to meet security, operational, and performance standards. These reviews include assessments of any new risks that may emerge over time. Rundoo retains the flexibility to modify vendor relationships as needed, without any guarantees or specific timetables.
4. Data Backup and Recovery
Rundoo maintains point-in-time backups of all critical databases, hosted on GCP, to ensure data recovery in the event of an incident or system failure. These backups enable the recovery of databases to any specific point in time. However, no guarantees are made regarding recovery timeframes or data loss prevention in every scenario.
5. Incident Response and Escalation
In the event of a security or operational issue involving a third-party vendor, Rundoo follows its incident management procedures (outlined separately) to promptly assess and mitigate the impact. Should a vendor fail to meet service expectations, Rundoo has the ability to switch vendors or roll back changes where feasible, though no guarantees are made about incident resolution or vendor replacement timelines.
6. Compliance and Data Protection
Each third-party provider is responsible for complying with applicable data protection regulations, including GDPR and CCPA, where relevant. Rundoo monitors vendors for compliance but does not guarantee that all risks are mitigated or that all third-party providers will meet every regulatory requirement at all times.
7. Program Modifications
Rundoo reserves the right to update or amend this Program at any time, based on evolving third-party risks, changes in vendors, or new legal requirements. No specific outcomes are guaranteed as part of this Program.
8. Disclaimer
This Program is provided as a general guideline for managing third-party risks. It does not create any legal obligations or warranties regarding the security, performance, or reliability of third-party services. Rundoo disclaims liability for any damages or losses resulting from third-party failures or service disruptions.
Rundoo Enterprise-Wide Security Awareness Program Policy
1. Overview
The Rundoo Enterprise-Wide Security Awareness Program (“Program”) establishes a framework for educating and training all employees and contractors on best practices for information security. This Program aims to reduce security risks by promoting awareness and reinforcing security protocols across the organization. The guidelines outlined in this Program are subject to change at Rundoo’s discretion and do not guarantee specific security outcomes.
2. Scope
This Program applies to all employees, contractors, and third-party service providers who access Rundoo’s systems, data, or infrastructure. It covers essential security awareness training during onboarding, ongoing peer review, and regular policy reviews.
3. Key Components of the Security Awareness Program
- Onboarding Training: All new employees and contractors must complete security awareness training as part of their onboarding process. This training covers the fundamentals of Rundoo’s security policies, including proper data handling, password management, access controls, and identifying potential security threats such as phishing attacks.
- Policy Review: As part of onboarding, all employees are required to review and acknowledge key security-related policies, including but not limited to the Information Security Program, Incident Management Program, Data Retention Policy, and Change Management Program. These documents serve as guidelines and must be reviewed periodically by all employees to ensure ongoing awareness.
- Peer Review: Rundoo incorporates peer review as a key element of maintaining security awareness across the organization. Engineers are required to submit code changes for peer review through GitHub, where team members assess not only the functionality but also the security impact of each change. This review process helps ensure that all team members actively participate in upholding Rundoo’s security standards.
4. Monitoring and Compliance
Rundoo’s security team monitors compliance with the Security Awareness Program. Employees who fail to complete required training or demonstrate poor security practices may be subject to additional training or corrective action. However, Rundoo does not guarantee the complete prevention of security incidents as a result of this Program.
5. Program Modifications
Rundoo reserves the right to modify or update this Program at any time, based on new security threats, changes in company operations, or legal requirements. Employees will be notified of significant changes, but no specific outcomes or timelines are guaranteed.
6. Disclaimer
This Security Awareness Program is intended as a general framework for promoting security awareness at Rundoo. It does not create any contractual rights or obligations, nor does it guarantee the prevention of security incidents. Rundoo disclaims any liability for incidents or breaches resulting from non-compliance or unforeseen security risks.
Rundoo Security Function and Role Policy
1. Overview
The Rundoo Security Function and Role Policy (“Policy”) defines the responsibilities for maintaining and enforcing information security across the organization. While Rundoo’s Co-Founder & CTO, Andrew Beckman, is primarily responsible for establishing security standards, all employees play a role in upholding and practicing these standards. This Policy serves as a guideline and is subject to change at Rundoo’s discretion.
2. Scope
This Policy applies to all employees, contractors, and third-party service providers. It outlines the division of responsibility for ensuring the confidentiality, integrity, and availability of Rundoo’s systems and data.
3. Roles and Responsibilities
- Andrew Beckman, Co-Founder & CTO: Andrew Beckman is the primary person responsible for setting Rundoo’s information security standards. He oversees the development, implementation, and maintenance of security policies, processes, and controls. Andrew evaluates security risks, approves security-related changes, and ensures compliance with relevant laws and industry standards. While he leads the overall security program, he does not guarantee the elimination of all risks.
- All Employees: Every employee and contractor at Rundoo is responsible for maintaining good security practices. This includes, but is not limited to:
- Protecting sensitive data and ensuring proper data handling.
- Following Rundoo’s security policies and reporting any potential security incidents or vulnerabilities.
- Password Management: All passwords used by Rundoo employees must be stored in 1Password, and no passwords should be kept or managed outside of this system. This ensures that access credentials are securely stored and protected with strong encryption.
- Using strong, unique passwords and adhering to multi-factor authentication (MFA) requirements.
- Ensuring that any changes they make to systems or processes undergo peer review and follow established security protocols.
4. Employee Involvement
While Andrew Beckman sets the overall security direction, security is a shared responsibility across all departments. Employees are expected to stay informed about security best practices and participate in security-related training during onboarding. By following the policies set forth, employees contribute to maintaining the security and integrity of Rundoo’s systems.
5. Program Modifications
Rundoo reserves the right to modify or update this Policy at any time without prior notice. Adjustments may be made based on changes in security risks, legal requirements, or operational needs.
6. Disclaimer
This Policy serves as a general framework for security responsibilities at Rundoo. It does not create any contractual rights or obligations, nor does it guarantee specific security outcomes. Rundoo disclaims any liability for security incidents resulting from employee actions or unforeseen threats.
Rundoo Software and Hardware Management Policy
Purpose:
To establish and document Rundoo’s approach for maintaining an accurate and up-to-date inventory of all critical hardware and software assets utilized across the organization. This policy aims to secure sensitive data, ensure business continuity, and streamline access controls while allowing Rundoo flexibility in evolving its processes as necessary.
Scope:
This policy applies to all hardware assets issued to Rundoo employees and to the software, tools, and systems used to develop, deploy, and operate Rundoo’s technology solutions.
Policy:
- Software Inventory Management: Rundoo’s production and operational software assets are managed through a centralized repository in GitHub. All code, documentation, and configurations relevant to Rundoo’s technology stack are maintained within GitHub’s secure environment. This includes the following measures:
- Source Control: All software code and dependencies are managed in GitHub repositories. Versioning, permissions, and audit trails are enforced to protect the integrity and confidentiality of production software.
- Access Control: Access to the GitHub repositories is restricted to authorized personnel based on job function. Access is provisioned and deprovisioned according to employee roles and updated with organizational changes.
- Monitoring and Auditing: GitHub’s logging and monitoring capabilities are used to track modifications and access, ensuring software integrity and accountability.
- SaaS Services Access and Inventory: Rundoo uses various third-party Software-as-a-Service (SaaS) solutions to manage operations, finance, marketing, and customer relations. Access to these services is managed exclusively through Google’s Single Sign-On (SSO) integration, providing secure authentication and streamlined access control.
- Provisioning: SaaS access is granted to employees upon onboarding, with permission levels aligned with their job functions and responsibilities. Access requests and changes are facilitated through Google’s SSO interface to enforce access control protocols.
- Deprovisioning: Access to SaaS applications is automatically revoked upon employee exit or role change. Regular access reviews are conducted to ensure continued compliance with Rundoo’s access policies.
- Inventory Management: A comprehensive inventory of SaaS applications and associated users is maintained by the Operations team and updated regularly to reflect organizational changes.
- Hardware Asset Management: All hardware assets, including laptops, mobile devices, and other equipment provided by Rundoo to employees, are tracked and managed upon issuance.
- Onboarding and Allocation: Each new employee is issued hardware necessary for their role, and details are recorded in the asset management system. This record includes the device type, serial number, issue date, and assigned employee.
- Inventory Tracking and Auditing: The asset management system is periodically reviewed and audited to ensure that records accurately reflect the current allocation of hardware across the organization.
- Decommissioning and Retrieval: Upon employee exit or hardware upgrade, devices are returned, sanitized, and reissued as appropriate. Rundoo reserves the right to retrieve and decommission hardware to maintain an accurate and efficient inventory.
- Policy Amendments and Revisions: Rundoo retains the right to amend or revise this Inventory Management Policy to adapt to changes in technology, business needs, and regulatory requirements. Employees will be notified of any significant changes to the policy.
Compliance:
All Rundoo employees are expected to adhere to this policy. Non-compliance may result in disciplinary actions, including but not limited to the revocation of access privileges and/or termination of employment.
Rundoo Data Classification Policy
Purpose:
To establish a data classification system that defines the levels of sensitivity for all data assets at Rundoo. This policy ensures appropriate handling, access, and protection for information based on its sensitivity, thereby supporting regulatory compliance, safeguarding intellectual property, and protecting client data.
Scope:
This policy applies to all data created, accessed, or managed by Rundoo employees, contractors, or third-party providers on behalf of Rundoo. It encompasses electronic data stored on Rundoo systems, as well as physical records containing sensitive information.
Policy:
Rundoo classifies its data into four categories, each with distinct handling, access, and security requirements:
- Confidential Data
- Definition: Information that is highly sensitive, with disclosure likely to cause significant harm to Rundoo, its clients, or its partners. This category includes personally identifiable information (PII), client data, financial records, proprietary business information, and trade secrets.
- Access Control: Limited strictly to employees or third parties with a legitimate need-to-know basis. Access is granted only through secure authentication mechanisms.
- Handling Requirements:
- Storage: Confidential data must be stored in encrypted form, whether at rest or in transit.
- Transmission: Transmission of Confidential data must occur over secure, encrypted channels (e.g., HTTPS, VPN).
- Destruction: Secure deletion and destruction methods must be used when disposing of Confidential data, such as secure file shredding or physical destruction for printed materials.
- Restricted Data
- Definition: Information sensitive to Rundoo’s operations but less critical than Confidential data. This includes operational plans, internal project documents, and internal communications that do not contain highly sensitive details.
- Access Control: Accessible to Rundoo employees who require access for legitimate business purposes, subject to manager approval and access logging.
- Handling Requirements:
- Storage: Restricted data may be stored in standard internal systems, with access control and monitoring.
- Transmission: Should be shared internally through secure channels and externally only when necessary, using approved encryption methods.
- Destruction: Standard digital deletion methods may be applied, and physical copies must be securely shredded when no longer required.
- Internal Use Data
- Definition: Information intended for internal consumption that does not expose Rundoo to significant risk if disclosed. Examples include employee contact information, general operational procedures, and non-sensitive meeting notes.
- Access Control: Accessible to all Rundoo employees and contractors for internal purposes.
- Handling Requirements:
- Storage: Internal use data may be stored on standard systems without encryption but must still be safeguarded from unauthorized access.
- Transmission: Can be shared within Rundoo’s network but should be limited in external communication unless necessary.
- Destruction: Deletion when no longer required; physical documents should be discarded in a secure manner.
- Public Data
- Definition: Information intended for public distribution or already available to the public. This includes marketing materials, published blog posts, press releases, and public website content.
- Access Control: Accessible by anyone, including external stakeholders and the general public.
- Handling Requirements:
- Storage: No specific storage requirements, but should remain accurate and up-to-date.
- Transmission: Freely shareable with the public.
- Destruction: No specific requirements, but regular review for accuracy and relevance is recommended.
- Data Classification Responsibilities:
- Employees and Contractors: Must classify information appropriately, handle it according to its classification level, and report any incidents of mishandling or data breaches.
- Managers: Responsible for ensuring that their team members are trained in data classification standards and for reviewing access permissions regularly.
- IT and Security Team: Responsible for providing tools and resources to secure data, monitoring for policy adherence, and assisting in the resolution of security incidents.
Policy Review and Amendments:
Rundoo retains the right to review and amend this Data Classification Policy as needed. All employees and contractors will be notified of any material changes and are required to comply with the latest version of this policy.
Compliance:
Failure to comply with this Data Classification Policy may result in disciplinary action, up to and including termination of employment or contract.
Rundoo Access Control Policy
Purpose:
The purpose of this Access Control Policy is to establish guidelines for requesting, approving, and monitoring access to Rundoo’s software and hardware assets. This policy ensures that access is granted on an “as-needed” basis to support business operations while maintaining data security, regulatory compliance, and system integrity.
Scope:
This policy applies to all Rundoo employees, contractors, and any third parties with authorized access to Rundoo’s software applications, systems, and devices.
Policy:
- Access Request
- Initiation: Access to software, systems, and devices must be requested by the employee or contractor’s manager based on the individual’s job responsibilities and business needs.
- Request Submission: Requests must be submitted through Rundoo’s designated access management system or, where unavailable, in writing to the IT and Security Team for tracking and auditing purposes.
- Eligibility: Access requests are reviewed to ensure they align with the user’s role and level of access required for their responsibilities.
- Access Approval
- Approval Process: All access requests must be reviewed and approved by both the requestor’s manager and the IT and Security Team.
- Principle of Least Privilege: Access is provisioned based on the principle of least privilege, granting users only the minimum access necessary to perform their roles.
- Documentation: Approved requests are documented, including justification, access levels granted, and the approvers’ identities, to ensure an audit trail and compliance with security policies.
- Access Provisioning
- Software and Systems: Access to applications, databases, and internal systems is provisioned by the IT and Security Team upon approval and configured to match the specified access level.
- Devices: Device access, including laptops, tablets, and other company-owned hardware, is issued by the Operations team upon approval and tracked in the asset management system.
- Single Sign-On (SSO): Where available, access to SaaS applications and systems is provisioned through Google’s Single Sign-On (SSO) to centralize authentication and improve security.
- Multi-Factor Authentication (MFA): Multi-factor authentication is required for access to all high-risk systems to provide an additional layer of security beyond passwords. This includes sensitive databases, production environments, and any other systems deemed critical by the IT and Security Team.
- Password Requirements and Management: Rundoo enforces platform-based password requirements for all accounts, and all passwords must be managed in 1Password to ensure security and centralized control. Inactivity lockouts are enabled where appropriate to reduce the risk of unauthorized access to unattended systems.
- Ongoing Access Monitoring
- Periodic Reviews: Access levels are reviewed quarterly to verify continued necessity based on the user’s role and responsibilities. Access may be modified or revoked if no longer required.
- Real-Time Monitoring: DataDog and Google Cloud Monitoring are used to detect unauthorized access attempts or unusual activity on production systems, with automated alerts sent to the IT and Security Team.
- Deprovisioning: Access is immediately revoked upon employee or contractor exit, role change, or other business-related adjustments. All access credentials and device assignments are documented and terminated in alignment with offboarding procedures.
- Policy Amendments and Exceptions
- Policy Revisions: Rundoo retains the right to amend this policy as needed to adapt to evolving security threats, business requirements, or regulatory changes.
- Exceptions: Any deviations from this policy require documented approval from the IT and Security Team, with justification and a timeline for compliance.
Compliance:
All Rundoo personnel are required to comply with this policy. Non-compliance may lead to disciplinary action, up to and including termination of employment or contract.
Rundoo Disaster Recovery (DR) and Business Continuity Plan (BCP) Policy
Purpose:
This policy outlines Rundoo’s approach to disaster recovery and business continuity planning to ensure that critical business operations and information security controls are maintained in the event of a disruption. The policy provides recovery objectives and testing requirements to safeguard Rundoo’s operational resilience and client data protection.
Scope:
This policy applies to all systems, applications, data, and infrastructure critical to Rundoo’s operations and to any employees responsible for implementing, managing, or reviewing the DR and BCP plans.
Policy:
- Disaster Recovery (DR) and Business Continuity Plan (BCP) Requirements
- Rundoo maintains a formal Disaster Recovery (DR) Plan and Business Continuity Plan (BCP) that are designed to minimize the impact of disruptions and restore critical business operations.
- The DR and BCP plans cover all essential systems, including network protection, monitoring, and log management, to ensure continuity of information security controls during recovery.
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
- Recovery Time Objective (RTO): Rundoo’s RTO is set to ensure that all critical services are restored within 5 minutes following an incident, minimizing operational downtime.
- Recovery Point Objective (RPO): Rundoo’s RPO is set at 5 minutes for data, ensuring minimal data loss in the event of a disruption by leveraging continuous backups and redundant systems in Google Cloud Platform.
- Annual Testing and Review
- The DR and BCP plans are formally reviewed and tested on an annual basis to validate recovery processes, ensure alignment with operational changes, and confirm the effectiveness of security controls.
- Testing includes simulated scenarios to verify that recovery procedures meet the defined RTO and RPO standards and that data integrity, network security, and monitoring capabilities are upheld throughout the recovery.
- Documentation and Updates
- All DR and BCP activities, including tests, reviews, and plan updates, are documented and retained for audit purposes.
- Rundoo’s IT and Security Team is responsible for updating the DR and BCP plans to reflect new security requirements, infrastructure changes, or identified areas for improvement.
- Compliance
- Rundoo personnel are expected to follow the DR and BCP processes during a disruption, and non-compliance may result in disciplinary actions as per Rundoo’s security policies.
Policy Amendments:
Rundoo reserves the right to update this policy in response to evolving business needs, technology advancements, and regulatory changes.
