How Realm9 is built, hosted and secured
Realm9 governs the systems you cannot afford to get wrong. Here is our posture, in the level of detail your security team will ask for anyway.
Security foundations
Dedicated deployment
Dedicated single-tenant cloud environment per customer.
Enterprise identity
SAML 2.0 single sign-on, SCIM provisioning, and MFA through your identity provider.
Encryption
Encryption at rest and in transit.
Independent testing
Independent testing against production-equivalent Realm9 deployments.
Architecture and data handling
| Area | Position |
|---|---|
| Deployment security | Customer environments are provisioned in isolated cloud accounts or tenancies using standardised Infrastructure-as-Code and hardened baseline configurations. |
| Identity and access control | SAML 2.0 single sign-on, SCIM 2.0 user provisioning, MFA and Conditional Access through the customer identity provider, role-based access control, group-to-role mapping, and governed onboarding. |
| Data protection | Encryption at rest and in transit, secure secret management, restricted access to databases and storage, customer-specific infrastructure boundaries, and audit logging for access and configuration changes. |
| Approval controls | Role-based access control with governed approval workflows and environment-level governance controls. |
| Auditability | Detailed audit records span access, role changes, environment requests, approvals, provisioning, and administrative activity. Records are reviewable in-platform and exportable to your SIEM. |
| Infrastructure | IaC-driven provisioning with hardened cloud and network controls, private network boundaries, restricted management access, and database and storage isolation. |
| Vulnerability management | Security findings are tracked, remediated, and validated through security processes, with periodic independent security assessments. |
| Availability | 98% availability target for managed deployments. |
Penetration tested against a production-equivalent deployment
Realm9 undergoes independent penetration testing against an isolated deployment that reflects the architecture, controls, and configuration patterns used for customer environments.
Testing is performed on a dedicated, isolated cloud environment. This avoids impact to customer systems while preserving the deployment model used for private customer installations.
No Critical or High severity findings in the latest assessment
Detailed reports are available to customers, prospective customers, and auditors under NDA. Contact our team to request the latest penetration-testing summary.
Reporting a vulnerability
If you believe you have found a security issue in Realm9, contact security@realm9.app. We acknowledge within one business day and will keep you updated through to resolution. We do not pursue legal action against good-faith research.