RUMA CARE
Security & Compliance
Last updated: September 2026
Ruma protects the confidentiality, integrity, and availability of customer data through administrative, technical, and organizational safeguards.
Data protection
Customer data is encrypted in transit using HTTPS/TLS and encrypted at rest by our production infrastructure providers. Ruma limits the collection and use of data to what is necessary to provide our services.
Access controls
Access to Ruma systems is restricted according to job responsibilities and the principle of least privilege. The platform uses role-based permissions, organization-level data isolation, and supports multi-factor authentication. Access and significant system activity are logged for security review.
Infrastructure security
Ruma’s production platform uses established cloud infrastructure providers, including Vercel, Supabase, and AWS. We use managed firewall protections, monitoring, alerting, backups, and restricted administrative access to protect production systems.
Secure development
Application changes are version controlled, tested, reviewed, and deployed through controlled processes. We assess dependencies for known vulnerabilities and address security findings according to risk.
Incident response
Ruma maintains documented procedures for identifying, investigating, containing, and recovering from security incidents. Customers will be notified when required by applicable law or contractual obligations.
Privacy and healthcare data
Ruma is designed to support healthcare workflows involving protected health information. We maintain safeguards intended to support our customers’ HIPAA obligations and enter into Business Associate Agreements when applicable.
Compliance
Ruma is currently undergoing a SOC 2 Type II examination. Completion of the examination is pending, so this statement should not be interpreted as a claim that Ruma has already received a SOC 2 report.
Contact
To report a security concern, contact team@rumacare.com.

