Security & trust at Rezllynx.
Your guests’ personal data and your business data live inside Rezllynx. We take that responsibility seriously.
Certifications
- ISO 27001:2022 — Information security management, certified since 2020.
- PCI DSS Level 1 — Payment card industry compliance via Stripe partnership.
- UK GDPR & Data Protection Act 2018 — ICO registration ZA482763.
- Cyber Essentials Plus — Certified since 2019.
- SOC 2 Type II — Report available under NDA to enterprise customers.
Data hosting and residency
All customer data is processed and stored inside the UK and EEA, on AWS infrastructure in the London (eu-west-2) and Ireland (eu-west-1) regions.
Encryption
Data in transit uses TLS 1.3. Data at rest uses AES-256 encryption managed by AWS KMS.
Access controls
All employee access requires multi-factor authentication and is logged. Access is granted on a least-privilege basis, reviewed quarterly.
Vulnerability management
Annual penetration testing by NCC Group. Quarterly vulnerability scans of all internet-facing services.
Incident response
Detection and triage within 15 minutes of alert. Containment within 1 hour. Customer notification within 24 hours for personal data breaches.
Business continuity
Disaster recovery tested quarterly. RPO: 24 hours. RTO: 4 hours.
Sub-processors
- AWS — cloud infrastructure (UK and EU regions only).
- Stripe — payment processing.
- Postmark — transactional email.
- Intercom — customer support tooling.
- Mixpanel — aggregated product analytics only.
Reporting a security vulnerability
Email security@rezllynx.org with a proof-of-concept.
Contact
Security team: security@rezllynx.org
Data Protection Officer: compliance@rezllynx.org
General enquiries: support@rezllynx.org