Effective: July 6, 2026
Security is fundamental to how we build and operate RDS360. This page describes the technical and organizational measures we use to protect your data and our infrastructure.
RDS360 handles order, payment, and delivery data on behalf of restaurants, marketplaces, and delivery service providers. We treat that data as a serious responsibility. Our approach follows industry-standard security practices with an emphasis on defense in depth: multiple overlapping safeguards so no single failure exposes your information.
All communication between clients (web browsers, mobile apps, integrations) and our servers is encrypted using TLS 1.2 or higher. HTTPS is enforced across all customer-facing endpoints, and certificates are managed via a trusted certificate authority.
Customer data stored in our databases and object storage is encrypted at rest using AES-256. Backups are encrypted with the same standard.
Payment processing is handled by Stripe, a Level 1 PCI DSS-certified payment provider. Full payment card numbers are never stored on RDS360 servers. Card data is tokenized by Stripe, and only tokens are retained on our systems for the purpose of processing future transactions.
Webhook payloads from payment processors are cryptographically signature-verified before being processed. Payment disputes and chargebacks are handled through automated integration with Stripe.
The RDS360 platform is hosted on Amazon Web Services (AWS), a leading cloud infrastructure provider with SOC 2, ISO 27001, and PCI DSS certifications. Key infrastructure components:
We maintain continuous monitoring of our infrastructure, including application health, error rates, database performance, and security events. Our team is alerted to critical anomalies and follows a documented incident response process for suspected security incidents:
Databases are backed up daily with encrypted snapshots. We test our restore process regularly. In the event of a major infrastructure failure, backups can be restored to a new environment to minimize service disruption.
RDS360 operates a multi-tenant white-label platform where each tenant runs on isolated infrastructure. Each tenant has its own database and application server, ensuring strict logical and physical separation of data across tenants.
We work with third-party providers who meet our security standards. Key vendors — including Stripe, AWS, Cloudflare, Twilio, and Google — are enterprise-grade providers with their own robust security programs and compliance certifications.
We design our practices with the following frameworks in mind:
Found a security issue? We appreciate reports from security researchers. Please email getstarted@tryrds360.com with the subject line "Security Report" and include:
We ask that you not exploit the issue beyond what is necessary to demonstrate it, and that you give us reasonable time to remediate before public disclosure.
For security-related questions, contact getstarted@tryrds360.com.