Security

Effective: July 6, 2026

Security is fundamental to how we build and operate RDS360. This page describes the technical and organizational measures we use to protect your data and our infrastructure.

Our approach

RDS360 handles order, payment, and delivery data on behalf of restaurants, marketplaces, and delivery service providers. We treat that data as a serious responsibility. Our approach follows industry-standard security practices with an emphasis on defense in depth: multiple overlapping safeguards so no single failure exposes your information.

Data encryption

In transit

All communication between clients (web browsers, mobile apps, integrations) and our servers is encrypted using TLS 1.2 or higher. HTTPS is enforced across all customer-facing endpoints, and certificates are managed via a trusted certificate authority.

At rest

Customer data stored in our databases and object storage is encrypted at rest using AES-256. Backups are encrypted with the same standard.

Access controls

Payment security

Payment processing is handled by Stripe, a Level 1 PCI DSS-certified payment provider. Full payment card numbers are never stored on RDS360 servers. Card data is tokenized by Stripe, and only tokens are retained on our systems for the purpose of processing future transactions.

Webhook payloads from payment processors are cryptographically signature-verified before being processed. Payment disputes and chargebacks are handled through automated integration with Stripe.

Infrastructure

The RDS360 platform is hosted on Amazon Web Services (AWS), a leading cloud infrastructure provider with SOC 2, ISO 27001, and PCI DSS certifications. Key infrastructure components:

Application security

Monitoring and incident response

We maintain continuous monitoring of our infrastructure, including application health, error rates, database performance, and security events. Our team is alerted to critical anomalies and follows a documented incident response process for suspected security incidents:

  1. Detection and triage
  2. Containment
  3. Investigation and root-cause analysis
  4. Remediation
  5. Notification to affected parties (as required by law and contract)
  6. Post-incident review and process improvement

Backups and disaster recovery

Databases are backed up daily with encrypted snapshots. We test our restore process regularly. In the event of a major infrastructure failure, backups can be restored to a new environment to minimize service disruption.

Data isolation (multi-tenant)

RDS360 operates a multi-tenant white-label platform where each tenant runs on isolated infrastructure. Each tenant has its own database and application server, ensuring strict logical and physical separation of data across tenants.

Vendor and third-party management

We work with third-party providers who meet our security standards. Key vendors — including Stripe, AWS, Cloudflare, Twilio, and Google — are enterprise-grade providers with their own robust security programs and compliance certifications.

Employee security

Compliance

We design our practices with the following frameworks in mind:

Responsible disclosure

Found a security issue? We appreciate reports from security researchers. Please email getstarted@tryrds360.com with the subject line "Security Report" and include:

We ask that you not exploit the issue beyond what is necessary to demonstrate it, and that you give us reasonable time to remediate before public disclosure.

Questions

For security-related questions, contact getstarted@tryrds360.com.