01 · Hosting
EU-only hosting
- Primary: Hetzner Online GmbH — Frankfurt am Main (ISO 27001)
- Failover: OVHcloud SAS — Warsaw (failover under 4 minutes)
- Payments: Stripe Payments Europe Ltd (Dublin, PCI-DSS L1)
- Backups: Backblaze B2 EU cluster in Helsinki, AES-256 encrypted
No data processing outside the EU/EEA.
02 · Encryption
In transit and at rest
In transit
TLS 1.3 with perfect forward secrecy plus certificate pinning against the SiteMinder endpoints.
At rest
Every SiteMinder OAuth token is encrypted AES-256 in a separate secrets vault backed by a hardware HSM (Frankfurt).
Passwords
Argon2id (memory-hard) hashing for every Rmsclaud user account.
03 · Backups
3-2-1 rule · RPO < 15 min
- Daily snapshot backup (Frankfurt)
- Second copy in Warsaw, third in Helsinki
- 30-day rolling retention
- Restore SLA: RPO under 15 minutes, RTO under 4 hours
- Quarterly restore drills
04 · Access
Least privilege · MFA
- Production access via MFA plus hardware key (YubiKey) only
- Role-based access control
- No SSH password login
- Full audit log, retained 12 months
05 · Compliance
GDPR & SOC 2 pathway
- GDPR + Montenegro Personal Data Protection Act — fully aligned
- PCI-DSS — payment card data is out of scope, handled by Stripe
- SOC 2 Type II — engagement scoping in progress, Type I evidence pack available on request
06 · Disclosure
Vulnerability disclosure
Report vulnerabilities to compliance@rmsclaud.org. Confirmation within 24 hours, status update within 5 business days. Coordinated disclosure preferred.