Rallyware · Trust Center

Rallyware Trust Center

Trust center

Rallyware maintains a public trust center documenting SOC 2 and GDPR compliance.

CompanySales EnablementWorkforce EnablementLearning and DevelopmentPerformance ManagementGamificationDirect SellingEnterprise Software
Trust center: https://www.rallyware.com/security-2

Certifications & Compliance

SOC 2GDPR

Source

Trust Center

rallyware-trust-center.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.rallyware.com/security-2
url: https://www.rallyware.com/security-2
type: security posture page
dedicated_trust_portal: false
portal_note: >-
  No trust.rallyware.com or security.rallyware.com exists (both fail to resolve,
  probed 2026-08-14). What Rallyware publishes is a single narrative security page on
  the marketing site — no document request flow, no downloadable report, no
  subprocessor list, and no live control status.

certifications:
- SOC 2
- GDPR

certification_detail:
- name: SOC 2
  claim_text: >-
    "Our approach is based on the five SOC 2 Trust Service Criteria: security,
    availability, processing integrity, confidentiality and privacy."
  attestation_claimed: false
  caveat: >-
    Framed as the framework their approach is BASED ON. Rallyware does not claim a
    completed Type I or Type II attestation, does not name an auditing firm, does not
    state a report period, and offers no path to request the report. Record as
    published posture, not verified certification.
- name: GDPR
  claim_text: >-
    No explicit GDPR compliance statement appears on the security page. The signal is
    implementation-side: the site runs a GDPR cookie-consent implementation and
    publishes a privacy policy, and the API data model carries a GDPR erasure marker
    (UserProfile.deletion_requested_at) plus tenant-configurable privacy and cookie
    policy pages.
  attestation_claimed: false

not_claimed:
- ISO 27001
- ISO 27017
- ISO 27018
- PCI DSS
- HIPAA
- FedRAMP
- CSA STAR
- FIPS 140

programs:
- name: Information Security Management System (ISMS)
  detail: Documented, updated annually, reviewed through internal and external audits.
- name: Independent penetration testing
  detail: Conducted annually.
- name: Bug Bounty Program
  detail: See security/rallyware-vulnerability-disclosure.yml.
- name: Business continuity / disaster recovery
  detail: >-
    BCP and DRP developed and regularly tested, covering pandemic, crisis
    communication and disaster recovery scenarios.
- name: Personnel security and training
  detail: Security-culture and training program stated.

infrastructure:
  cloud: AWS
  detail: >-
    "Rallyware's infrastructure is built on AWS, following established security best
    practices. Each service is designed and maintained with reliability and data
    protection requirements in mind. Project environments are isolated."
  corroboration: >-
    Independently consistent with observed operations — the internal status page is
    fronted by AWS Cognito (eu-central-1) and the public github.com/rallyware org
    consists entirely of AWS Terraform modules (EKS, MWAA, SQS, Cognito, VPC, RDS).

evidence:
- source: https://www.rallyware.com/security-2
  http_status: 200
  keywords:
  - soc 2
  - gdpr
  - isms
  - penetration testing
  - bug bounty
  - business continuity
- source: https://trust.rallyware.com/
  result: does not resolve
- source: https://www.rallyware.com/security
  http_status: 200
  note: 302 redirect to /security-2, which is the canonical page.