SECURITY & COMPLIANCE

How we protect your data and keep the platform resilient.

Redline Tabletop is built with security in mind from the ground up. This page describes our data handling, access controls, audit logging and incident response practices.

Encrypted in transit and at rest

All traffic between your browser and our service is protected with TLS. Database storage is encrypted at rest by the managed backend provider, and credentials are never stored in plain text.

Row-level access control

Every exercise, inject and user record is protected by row-level security policies. Users can only read and write data they own, and reference data is read-only by design.

Audit logging

Generation runs, edits, exports and sign-in events are tied to authenticated user sessions. We log actions at the application level so you can trace who created or changed an exercise.

Server-side generation

AI generation and threat-intel retrieval happen entirely on the server. Exercise content and source citations are assembled before they reach your browser, so prompts and reference data are not exposed to client-side handling.

Incident response

If we become aware of a security issue, we will investigate, contain affected systems, notify impacted users without undue delay, and document root cause and remediation steps.

Data handling

What we store

We store account information (email, name, organisation), exercise configurations, generated exercise content, and threat-intel reference data. We do not store payment information; billing is handled by our payment provider.

How we use it

Your data is used to generate and display your exercises, maintain your library, and improve service reliability. We do not train generative AI models on customer exercise content, and we do not sell or share user data with third parties for marketing.

Retention

Exercises are retained while your account is active. You can delete exercises from your library at any time. If you close your account, associated exercise data is removed in line with our data retention policy.

Backups

The backend database is backed up automatically by the managed platform. Backups are encrypted and retained for a standard recovery window so we can restore service in the event of failure.

Compliance and review

Redline Tabletop is designed to help security teams produce evidence-rich tabletop exercises. Generated materials include citations and traceability to support your internal audit, board briefing and regulatory documentation workflows. While our architecture follows security best practices, customers remain responsible for assessing how the service fits their own compliance requirements.

For security questions, review requests or vulnerability reports, contact us at security@redlinetabletop.com.