This Is What Different Looks Like
Most agencies tell you they're different. We show you. Every claim on this page is verifiable and tested.
Security Controls
Verified protections for your data.
TLS 1.3 Encryption
All external connections are encrypted in transit with TLS 1.3, and HSTS is enforced on them.
SSH Key Authentication
Password authentication disabled system-wide. Access requires cryptographic key pairs only.
Default-Deny Firewall
Inbound traffic on the public interface is denied by default, with an explicit allow-list for the ports that must be reachable. Administrative SSH is not among them — it is reachable only over our private mesh network, never from the public internet.
SSH Intrusion Prevention
Automated threat detection monitors for suspicious SSH activity and blocks malicious IPs in real-time.
24/7 Monitoring & Alerting
Metrics, centralized log aggregation, and alert rules across the production stack — with a delivery path that has been tested by driving a real alert through it to a real inbox. A dashboard nobody is paged from is not monitoring.
Secrets Management
Credentials live in root-owned files with restricted permissions, outside the code tree and never committed to version control. Stored automation credentials are encrypted at rest under a dedicated encryption key, and secrets are delivered to services in a form that is not exposed on any queryable system property.
Endpoint Detection & Response
All seven Linux servers we operate run an EDR agent reporting to a central manager, with file-integrity monitoring and rule-based detection; Windows endpoints are covered separately by Microsoft Defender for Business. Coverage is confirmed at the manager — the only place that can prove a host's telemetry is actually being received — and a disconnected agent raises its own alert.
Encrypted Offsite Backups
Offsite copies are encrypted with AES-256 and 100,000-iteration key derivation before they leave the host, and held with a second independent storage provider. Recovery is proven, not assumed: the most recent off-box test restored real archives using only an escrowed copy of the key, never the live key on the server — and it included controls confirming a wrong key and a tampered archive are both rejected.
Tested Procedures, Documented Results
We don't just plan for disasters. We test recovery and publish the results.
| Metric | Target | Tested Result |
|---|---|---|
| Recovery Time (RTO) | 4 hours | Full-stack recovery time not yet measured |
| Recovery Point (RPO) | 24 hours | < 24 hours |
Our recovery target is four hours. All four offsite backup sets — automation workflows, client portal, Glyph and the credential vault — have been restored and verified against production data, with zero tables lost. We have not yet timed an end-to-end recovery of the full stack, so we publish no recovery-time figure. When we measure one, it will appear here.
Enterprise-Grade Foundation
Built on certified, enterprise-grade platforms.
Managed Database
A DigitalOcean-managed database cluster with encryption at rest, automated failover and maintenance windows handled by the provider. Connections require SSL and run over private networking.
Private Networking
All internal services communicate over an isolated VPC. Internal ports bound to localhost only. Database connections use private endpoints.
Hardened Containers
Every running container executes unprivileged with privilege escalation blocked and Linux capabilities dropped by default — verified against the running containers, not just the configuration files that declare it.
Health Monitoring
Health checks and automatic restart policies on the services that carry client workloads, plus a self-healing watchdog running every 60 seconds and an independent off-host observer.
Enterprise Cloud Platform
We build on DigitalOcean. DigitalOcean holds its own SOC 2 Type II and SOC 3 attestations covering the platform and data centres we run on — those attestations are DigitalOcean's, not ours. Our services sit on its managed database and private-network tiers.
3-Tier Backup Architecture
Automated local, remote and encrypted offsite backups with AES-256 encryption — a 30-day operational retention window backed by an immutable 180-day offsite tier. Backups are verified on a weekly schedule, and recoverability is demonstrated by documented restore tests rather than inferred from the backup completing.
Policies & Governance
Thirteen documented security policies and procedures, reviewed annually, each mapped to the controls that implement it.
Annual Reviews
Four formal compliance reviews completed and signed each year: Access Review, Risk Assessment, Vendor Review, and Disaster Recovery Test. Each is signed off with documented findings and remediation tracking, and the signed records are available to clients on request.
Risk Management
Formal risk register tracking 10 documented risks with severity ratings, mitigation strategies, and residual risk analysis. 43% overall risk reduction achieved through implemented controls.
Monitoring & Self-Healing
Systems that watch themselves and fix problems before you even notice.
Automated Health Checks
Automated monitoring spans the production services, the hosts they run on, and the external dependencies they call. Problems are detected in minutes, not hours, and the alert reaches a person rather than a dashboard.
Self-Healing Watchdog
When a service fails, automated recovery kicks in within 60 seconds. Container restarts, connection resets, and failover — all without human intervention.
Centralized Logging
Application, access and system logs are aggregated into centralized storage with long-term retention, giving us an audit trail for investigation and accountability.
AI-Powered Documentation Audit
Nightly automated audit verifies that documentation matches reality. Self-improving compliance that catches drift before it becomes a problem.
Common Questions
Are you SOC 2 or ISO 27001 certified?
While we'd eventually love to achieve these certifications, we don't hold them at this time. What we do hold is the underlying work: documented policies, signed annual reviews, tested restores, and controls we measure rather than assert. We're happy to walk a security team through any of it.
Can you complete our security questionnaire?
Yes. We answer questionnaires from the same measured evidence shown on this page, and we'll tell you plainly where a control is in place, where one is planned, and where a number is an estimate rather than a measurement.
Where is our data stored, and who else can reach it?
In managed database and object-storage services in the United States, plus an encrypted offsite copy with a second provider. We maintain a written inventory of every vendor that touches client data, what it receives, and why — available on request.
What happens if you have a security incident?
We follow a documented incident response plan with severity classification, defined escalation paths, evidence preservation, and a post-incident review. Notification obligations to affected clients are written into our agreements rather than left to discretion.
Security Questions?
For compliance documentation, security questionnaires, or vulnerability reports.
info@rogueai.techReady to Go Rogue?
Stop following the playbook that fails 65% of businesses. Take the first step toward automation that actually works.