Audit Logging
We store transaction and receipt data for your time as a realfast customer, enabling audit readiness and the ability to review company spend retroactively. You can track who did what, when, and why with detailed transaction histories.
Security
At realfast, safeguarding your data is integral to our company culture, operations, and product development. We take the responsibility of protecting your information very seriously.
We start by dotting the I's and crossing the T's. For the most up-to-date information on our compliance posture, contact security@realfast.ai
Product security
We store transaction and receipt data for your time as a realfast customer, enabling audit readiness and the ability to review company spend retroactively. You can track who did what, when, and why with detailed transaction histories.
We apply the same access, authentication, and logging controls to model providers such as OpenAI, Gemini, and Claude and to cloud providers such as AWS, Google Cloud, and Azure.



Currently, all businesses have access to Sign In with Google, but we will add other SSO providers soon.
We notify you of any updates to your account's contact details, security settings, or login configuration.
We have granular permissions to ensure users only see what they need.
realfast retains multi-factor authentication for all users who sign in with an identity provider. Currently, we only allow logins with Google.
Monitoring
realfast logs failed and successful logins, application access, admin changes, and system changes. We continuously monitor critical systems for potential threats, with automated logging and alerting.
realfast employs a 24/7 Security Operations Center (SOC) that continuously monitors our network for potential threats. The SOC combines automated tools and human expertise to detect, analyze, and respond to security events in real time.
We are designing our systems based on the principles of Zero Trust. This means that no user or device is automatically trusted, regardless of whether they are inside or outside the network perimeter. Every access request is authenticated, authorized, and encrypted before access is granted.
Code security
realfast performs static code analysis on every pull request for our core services. This combines industry-standard scanners with a custom ruleset that detects potential vulnerabilities specific to our architecture. We continuously review and enhance our rulesets, prioritizing high-signal rules developed in-house. Code that fails any of these critical rules cannot be merged or deployed.
Designated engineering teams at realfast complete secure development training. Our Konfirmity program also briefs the engineering organization on vulnerabilities found in our applications, their mitigations, and security issues relevant to our stack.
All our public endpoints employ a managed Web Application Firewall to deter attempts to exploit common vulnerabilities.
Access control
We grant access according to job responsibilities and business need. Periodic reviews confirm that permissions remain appropriate and remove them when they are no longer required.
Our Security Information and Event Management (SIEM) system collects and analyzes logs from critical systems. Automated alerts notify the security team of suspicious activity.
Our password policies align with ISO 27001. Employees use a password manager to create unique passwords, and sensitive systems require multi-factor authentication (MFA).
Operations
realfast uses G-Suite capabilities to defend employee inboxes against various attacks. Suspicious emails are automatically flagged and quarantined based on rules and employee reports. Sensitive inbox contents are locked after a defined period of time, requiring re-authentication before interacting with password reset emails.
Every realfast employee completes security awareness training during onboarding. It covers phishing, reporting, handling sensitive data, and required security procedures. Refresher courses and simulated phishing exercises reinforce the training.
realfast maintains an incident response team and a tested response plan covering containment, investigation, and remediation. Report a security event to security@realfast.ai; the response team will take ownership.
An external party performs our annual internal risk assessment. We run additional assessments after significant changes to infrastructure, products, or business practices. Our compliance system monitors security controls and checks employee workstations continuously.
Infrastructure
realfast hosts its infrastructure in the AWS Mumbai region. AWS provides data-center access controls, continuous monitoring, regular audits, encryption at rest, network segmentation, and monitoring and logging services.
We are establishing a business continuity and disaster recovery (BC/DR) program. This includes a BC/DR plan, business impact analysis (BIA), risk assessments, and procedures for monitoring and improving the program. The plan guides responding, recovering, and resuming operations during severe events. To ensure essential business processes remain operational, it covers the personnel, resources, services, and actions required for this. The BC/DR plan will be tested annually.
We plan to implement an industry-standard web application firewall (WAF) to protect our services from DDoS attacks and help deter attempts to exploit common vulnerabilities.
We use AWS VPCs and IAM policies to isolate our production environment. Systems from one environment are not permitted to communicate with other environments.
Devices
All realfast-issued devices are required to have full disk encryption enabled. This ensures that data stored on these devices remains secure even in the event of loss or theft.
We employ a Mobile Device Management (MDM) solution to enforce security policies on all corporate endpoints. realfast enforces encryption, strong password policies, and automatic locking, and keeps operating systems and security patches up-to-date.
We use AWS's managed threat detection service to proactively identify and respond to potential threats. This service continuously monitors endpoints for any signs of malware, unauthorized access, or other suspicious activities. When threats are detected, the service notifies you immediately and recommends potential remedies.
Data
We use AES-256 Encryption for data at rest, and TLS 1.2+ Encryption for data in transit. realfast avoids storing sensitive customer information wherever possible. For example, your credit card numbers related to billing are not stored on our systems and instead reside with our sub-processors.
We use AWS AP-South-1 for automated backups. Backups are encrypted and are retained for at least 30 days, with access restricted by user role in AWS.
Our data centers are hosted by Amazon Web Services (AWS), which makes our security as good as AWS's Physical Security controls.
Questions about how we handle your data? Reach us at security@realfast.ai.
Book a discovery call