XXcellerate
Trust

How Xcellerate protects your data.

Last updated: 2 August 2026 · Version 1.0

1

Scope

This security statement describes the administrative, technical and organisational measures RMM Labs Ltd operates to protect personal data and customer content within the Xcellerate OPS managed cloud and the related corporate infrastructure. It is published in fulfilment of GDPR Art. 32 and is incorporated by reference into the data processing addendum.

2

Governance

  • An information-security policy is reviewed at least every six months, or sooner if a material change occurs.
  • Roles and responsibilities are aligned to the ISO/IEC 27001:2022 control set.
  • A named function has operational accountability for security and reports at senior management level within RMM Labs Ltd. The function-holder is recorded in our internal register of processing activities under GDPR Art. 30 and is available on request under NDA.
3

Personnel security

  • Background screening is performed proportional to role sensitivity for personnel with access to production data.
  • Confidentiality undertakings bind all staff and contractors.
  • Security-awareness training is delivered at induction and at least every six months thereafter.
4

Access control

  • Least-privilege access based on documented roles.
  • Multi-factor authentication is required for all access to production systems and administrative consoles.
  • Access reviews are performed at least quarterly and recorded.
5

Cryptography and key management

  • TLS is enforced on every external endpoint; certificates are issued and renewed automatically via Let’s Encrypt.
  • At-rest encryption protects tenant data, and tenant TLS private keys are encrypted at rest in the master database with per-domain isolation.
  • Customer content is logically segregated by tenant identifier, and each Xcellerate OPS tenant runs against its own database.
6

Network security

  • Production networks are segmented from corporate networks.
  • Egress filtering, default-deny rules and a managed load-balancing layer sit in front of public endpoints.
  • Outbound dependencies are limited to documented, per-tenant integrations and are triaged by the security team.
7

Service continuity — an important distinction

RMM Labs Ltd distinguishes a commercial availability commitment from a personal-data availability duty.

  • Commercial availability: service-level terms for Xcellerate OPS are governed by the subscription agreement.
  • Personal-data availability (binding regardless of any commercial SLA): RMM Labs Ltd maintains backups of customer content sufficient to restore availability of and access to personal data in a timely manner following a physical or technical incident, in accordance with GDPR Art. 32(1)(b) and (c). Backups are stored in the EU region described in the compliance page.
8

Logging, monitoring and incident response

  • Centralised logging covers authentication, administrative and data-access events with tamper-evident retention.
  • An incident-response process operates with named on-call coverage.
  • Security incidents involving personal data are triaged against the breach-notification duties in GDPR Art. 33 and 34, and the NIS2 incident-reporting duties in Directive (EU) 2022/2555 Art. 23, where applicable.
  • Customers are notified of a confirmed personal-data breach without undue delay and in any event within the timescales in the data processing addendum.

Two retention classes apply: service-event logs, whose retention is configurable by the customer in tenant settings; and RMM-Labs-personnel access logs to customer content, whose retention is fixed at a minimum of 12 months and cannot be reduced by the customer, as this is necessary for GDPR Art. 32 and incident response.

9

Vendor management

  • A due-diligence process for sub-processors is documented.
  • Each sub-processor is bound by data-processing terms consistent with GDPR Art. 28.
10

AI-specific security

  • A human approval boundary sits on every AI action that creates a legal or significant effect (see the AI transparency statement).
  • Internal notes, secrets-vault entries, IT documentation and cost figures are never sent to AI providers.
  • Before any prompt leaves the platform, a deterministic, always-on redaction layer replaces personal and secret data (emails, phone numbers, IP and MAC addresses, IBANs, card and VAT numbers, API and bearer tokens) with stable placeholders; no AI is involved, so it cannot leak.
  • AI features run on the platform operator’s configured providers with API keys stored encrypted and never echoed back.
11

Customer controls

Customers may, in writing, request a copy of the current security-questionnaire responses at [email protected]. Penetration-test summaries may be made available under NDA.

12

Certifications

RMM Labs Ltd aligns to the ISO/IEC 27001:2022 control set and is pursuing third-party certification. Status: in progress. Independent certifications will be added to this section when issued.