Security and trust
How this site, and our engagements, handle your data.
Written for the person who has to approve us. Every control below is one you can verify from outside — view source, read the headers, run the scanners — and the ones we have not done yet are listed with dates.
This website
- Static site
- Pre-built HTML served from GitHub Pages over HTTPS only (HTTP redirects); no server-side code runs when you load a page, so there is no session, no login and no database behind it.
- Content Security Policy
- A strict CSP computed at build time: scripts and styles only from this origin (hash-allowed), images from this origin and data URIs, fonts from this origin, connections and form posts only to our own API endpoint, no object embeds, base URI locked.
- No cookies, no trackers
- No analytics, no advertising pixels, no chat widgets, no fonts from third parties. Theme and announcement choices are kept in your browser's local storage and never sent to us.
- Forms
- The contact form and the Readiness Score's optional email POST to our own serverless API on AWS in the Mumbai (ap-south-1) region: rate-limited, honeypot-protected, stored in DynamoDB, notification by Amazon SES to our mailbox. Retention is in the privacy notice.
- Demo videos
- Self-hosted MP4 files on this origin; nothing loads until you press play; no third-party player.
- Disclosure
- security.txt at /.well-known/security.txt; reports to security@rainkernel.com; we acknowledge within two working days and credit reporters who want credit.
Engagements
- Inside your cloud
- Engines, gateways and recorders run in your AWS, Azure or GCP estate under your IAM. We ask for scoped roles, never shared credentials, and we remove them at hand-over.
- No copies, no training
- We do not copy production data out of your environment and we train nothing on client data. Working copies are deleted within 30 days of a written request.
- Named engineers under NDA
- Access is limited to named engineers bound by the NDA in the master services agreement; the list is in the statement of work.
- Evidence stays with you
- Evaluation sets, reports, logs and BOMs are generated in your estate and are yours. We keep the invoice and, with permission, an anonymised reference.
- Sub-processors
- For this website and our correspondence: Amazon Web Services (Mumbai), GitHub (Pages), Microsoft 365 (email). For engagements: none without written agreement.
- Jurisdiction
- Rainkernel Technologies Private Limited is incorporated in India and processes personal data under the DPDP Act 2023; for EU and UK clients we act as a processor under the GDPR and UK GDPR on written instructions.
What we have not done yet
- Now
security.txt, strict CSP, HTTPS-only, no third-party code, documented sub-processors, NDA and MSA templates.
- Q1 2027
Externally reviewed security questionnaire (CAIQ-style) published here; penetration test of the API endpoint by a third party.
- 2027
ISO/IEC 27001 and ISO/IEC 42001 readiness assessment of Rainkernel itself — we will not sell 42001 evidence without working toward the certificate ourselves.
Questions for a security review, a vendor questionnaire or a data-processing agreement: security@rainkernel.com. Privacy requests: privacy@rainkernel.com. Related: Privacy notice · Cookie policy · Terms.