SECURITY & COMPLIANCE
How we protect your data and keep the platform resilient.
Redline Tabletop is built with security in mind from the ground up. This page describes our data handling, access controls, audit logging and incident response practices.
Encrypted in transit and at rest
All traffic between your browser and our service is protected with TLS. Database storage is encrypted at rest by the managed backend provider, and credentials are never stored in plain text.
Row-level access control
Every exercise, inject and user record is protected by row-level security policies. Users can only read and write data they own, and reference data is read-only by design.
Audit logging
Generation runs, edits, exports and sign-in events are tied to authenticated user sessions. We log actions at the application level so you can trace who created or changed an exercise.
Server-side generation
AI generation and threat-intel retrieval happen entirely on the server. Exercise content and source citations are assembled before they reach your browser, so prompts and reference data are not exposed to client-side handling.
Incident response
If we become aware of a security issue, we will investigate, contain affected systems, notify impacted users without undue delay, and document root cause and remediation steps.
Data handling
What we store
We store account information (email, name, organisation), exercise configurations, generated exercise content, and threat-intel reference data. We do not store payment information; billing is handled by our payment provider.
How we use it
Your data is used to generate and display your exercises, maintain your library, and improve service reliability. We do not train generative AI models on customer exercise content, and we do not sell or share user data with third parties for marketing.
Retention
Exercises are retained while your account is active. You can delete exercises from your library at any time. If you close your account, associated exercise data is removed in line with our data retention policy.
Backups
The backend database is backed up automatically by the managed platform. Backups are encrypted and retained for a standard recovery window so we can restore service in the event of failure.
Compliance and review
Redline Tabletop is designed to help security teams produce evidence-rich tabletop exercises. Generated materials include citations and traceability to support your internal audit, board briefing and regulatory documentation workflows. While our architecture follows security best practices, customers remain responsible for assessing how the service fits their own compliance requirements.
For security questions, review requests or vulnerability reports, contact us at security@redlinetabletop.com.