Security & trust at Rezllynx.

Your guests’ personal data and your business data live inside Rezllynx. We take that responsibility seriously.

Certifications

  • ISO 27001:2022 — Information security management, certified since 2020.
  • PCI DSS Level 1 — Payment card industry compliance via Stripe partnership.
  • UK GDPR & Data Protection Act 2018 — ICO registration ZA482763.
  • Cyber Essentials Plus — Certified since 2019.
  • SOC 2 Type II — Report available under NDA to enterprise customers.

Data hosting and residency

All customer data is processed and stored inside the UK and EEA, on AWS infrastructure in the London (eu-west-2) and Ireland (eu-west-1) regions.

Encryption

Data in transit uses TLS 1.3. Data at rest uses AES-256 encryption managed by AWS KMS.

Access controls

All employee access requires multi-factor authentication and is logged. Access is granted on a least-privilege basis, reviewed quarterly.

Vulnerability management

Annual penetration testing by NCC Group. Quarterly vulnerability scans of all internet-facing services.

Incident response

Detection and triage within 15 minutes of alert. Containment within 1 hour. Customer notification within 24 hours for personal data breaches.

Business continuity

Disaster recovery tested quarterly. RPO: 24 hours. RTO: 4 hours.

Sub-processors

  • AWS — cloud infrastructure (UK and EU regions only).
  • Stripe — payment processing.
  • Postmark — transactional email.
  • Intercom — customer support tooling.
  • Mixpanel — aggregated product analytics only.

Reporting a security vulnerability

Email security@rezllynx.org with a proof-of-concept.

Contact

Security team: security@rezllynx.org
Data Protection Officer: compliance@rezllynx.org
General enquiries: support@rezllynx.org