Rainkernel

Security and trust

How this site, and our engagements, handle your data.

Written for the person who has to approve us. Every control below is one you can verify from outside — view source, read the headers, run the scanners — and the ones we have not done yet are listed with dates.

This website

Static site
Pre-built HTML served from GitHub Pages over HTTPS only (HTTP redirects); no server-side code runs when you load a page, so there is no session, no login and no database behind it.
Content Security Policy
A strict CSP computed at build time: scripts and styles only from this origin (hash-allowed), images from this origin and data URIs, fonts from this origin, connections and form posts only to our own API endpoint, no object embeds, base URI locked.
No cookies, no trackers
No analytics, no advertising pixels, no chat widgets, no fonts from third parties. Theme and announcement choices are kept in your browser's local storage and never sent to us.
Forms
The contact form and the Readiness Score's optional email POST to our own serverless API on AWS in the Mumbai (ap-south-1) region: rate-limited, honeypot-protected, stored in DynamoDB, notification by Amazon SES to our mailbox. Retention is in the privacy notice.
Demo videos
Self-hosted MP4 files on this origin; nothing loads until you press play; no third-party player.
Disclosure
security.txt at /.well-known/security.txt; reports to security@rainkernel.com; we acknowledge within two working days and credit reporters who want credit.

Engagements

Inside your cloud
Engines, gateways and recorders run in your AWS, Azure or GCP estate under your IAM. We ask for scoped roles, never shared credentials, and we remove them at hand-over.
No copies, no training
We do not copy production data out of your environment and we train nothing on client data. Working copies are deleted within 30 days of a written request.
Named engineers under NDA
Access is limited to named engineers bound by the NDA in the master services agreement; the list is in the statement of work.
Evidence stays with you
Evaluation sets, reports, logs and BOMs are generated in your estate and are yours. We keep the invoice and, with permission, an anonymised reference.
Sub-processors
For this website and our correspondence: Amazon Web Services (Mumbai), GitHub (Pages), Microsoft 365 (email). For engagements: none without written agreement.
Jurisdiction
Rainkernel Technologies Private Limited is incorporated in India and processes personal data under the DPDP Act 2023; for EU and UK clients we act as a processor under the GDPR and UK GDPR on written instructions.

What we have not done yet

  1. Now

    security.txt, strict CSP, HTTPS-only, no third-party code, documented sub-processors, NDA and MSA templates.

  2. Q1 2027

    Externally reviewed security questionnaire (CAIQ-style) published here; penetration test of the API endpoint by a third party.

  3. 2027

    ISO/IEC 27001 and ISO/IEC 42001 readiness assessment of Rainkernel itself — we will not sell 42001 evidence without working toward the certificate ourselves.

Questions for a security review, a vendor questionnaire or a data-processing agreement: security@rainkernel.com. Privacy requests: privacy@rainkernel.com. Related: Privacy notice · Cookie policy · Terms.

Need a security questionnaire answered?

Send it. We answer vendor questionnaires in full, in writing, within five working days, and we will tell you which controls are in place today and which are dated.