Trust
Data security
RampedUp manages large-scale contact and company data, and data security is a core priority. Data is encrypted with AES-256 via AWS KMS at rest and TLS 1.2 in transit, access is role-based and least-privilege, and a formal incident response plan is in place. RampedUp reported no personal data breaches in the prior three years.
Every policy behind this page is downloadable. Jump to the Security Documentation Library →
Policy framework
RampedUp manages large-scale contact and company data, and data security is a core priority. We maintain formal, documented information security policies and procedures that are approved by senior management, communicated to staff and available for reference, assigned clear ownership and responsibilities, enforced with disciplinary provisions for non-compliance, and reviewed periodically for continued relevance.
Employees acknowledge codes of conduct and confidentiality obligations. Vendor risk assessments and supporting policies are maintained, including a 23-point vendor risk assessment for key suppliers.
Infrastructure, hosting and third parties
RampedUp is hosted on Amazon Web Services. Backups use AWS Key Management Service (KMS) with AES-256 encryption, and AWS Backup with automatic redundancy restoration.
Third-party and sub-processor review is a structured process. The sub-processor list is published publicly.
Data protection and encryption
Data in transit is protected with TLS 1.2. Data at rest uses industry-standard strong encryption, including AES-256 via AWS KMS.
On account expiration or closure, data is removed by cryptographic erasure. Administrators hold deletion permissions, with secure procedures at contract end.
Access control and authorized users
Only formally authorized users may access RampedUp systems, each with a unique user identity. RampedUp employees do not have access to customer passwords.
Access is role-based across System Administration, Instance Administration and User roles, designed around least-privilege access.
Password policy
Strong passwords are required: at least 12 characters with a mix of upper and lowercase letters, numbers and special characters. Passwords change every 90 days, the last five passwords cannot be reused, and ten failed login attempts trigger a lockout.
Violations can result in loss of access, disciplinary action, or legal consequences.
Retention and deletion
Undefined datasets are not republished after a set period — 15 months, for example. Data minimization is applied as a principle, and data is deleted by cryptographic erasure at contract end.
RampedUp does not source data from sites targeted at minors.
Monitoring, logging and incident response
A formal Incident Response Plan covers preparation through follow-up. AWS CloudTrail and VPC Flow Logs provide logging, with monitoring logs retained for approximately 30 to 90 days. Systems can be isolated through security group changes.
Breach notification and history
Affected customers are notified within 72 hours of breach awareness, aligned with GDPR. Impacted persons are notified within 14 business days.
RampedUp reported no personal data breaches in the prior three years.
Business continuity and disaster recovery
The business continuity management system is aligned with ISO 22301 — aligned, but not formally certified. Documented business continuity and disaster recovery procedures are tested periodically.
Critical data is backed up offsite through AWS Backup with encrypted, redundant storage, against clear recovery objectives with regular testing.
Governance, training and compliance
Security and privacy awareness training is provided to key staff. RampedUp complies with applicable local privacy laws inside and outside the United States, including EU and UK data protection law and US state privacy laws such as CCPA/CPRA, and maintains a Data Protection Officer function.
The AWS SOC 3 Security, Availability, Confidentiality and Privacy report is publicly available documentation.
RampedUp cloud hosting: AWS certifications
RampedUp runs on AWS, so AWS’s own certifications are part of our control environment. Both are independently audited and published by AWS.
ISO 27001:2022 certification for AWS
The certification provides a systematic approach to managing sensitive company information through a comprehensive framework of policies and procedures. The standard encompasses an organization’s people, processes, and IT systems, and directs the implementation of a strong risk management process. ISO 27001:2022, the latest version, introduces significant changes that include the restructuring of control categories and the addition of new controls focusing on threat intelligence and cloud security.
Key aspects of AWS physical and environmental controls — each links to that control in the AWS Trust Center:
- Secure Design
- Business Continuity & Disaster Recovery
- Physical Access
- Monitor & Logging
- Surveillance & Detection
- Device Management
- Operational Support Systems
- Infrastructure Maintenance
- Governance & Risk
SOC 3
AWS System and Organization Controls (SOC) Reports are independent third-party examination reports that demonstrate how AWS achieves key compliance controls and objectives. The purpose of these reports is to help you and your auditors understand the AWS controls established to support operations and compliance.
AWS SOC 3 Security, Availability, Confidentiality & Privacy Report
Both documents are published and maintained by AWS, so the links above always resolve to the current version rather than a copy we host.
Data broker registrations
Registered where registration is required, with the numbers so you can verify us independently.
| Jurisdiction | Registration number | Registry |
|---|---|---|
| California | 538248 | California Privacy Protection Agency (CPPA) Data Broker Registry |
| Oregon | 00344 | Oregon Department of Consumer and Business Services, Division of Financial Regulation |
| Texas | 20250186 | Texas Secretary of State |
| Vermont | 0409326 | Vermont Secretary of State |
RampedUp participates in the California Delete Request and Opt-out Platform (DROP), a centralized tool allowing California residents to submit a single request to have their personal data removed from hundreds of registered data brokers. Removal requests from any jurisdiction are honored through the do-not-sell portal; once confirmed, the person is removed from the database and every customer who downloaded that record is notified.
Security Documentation Library
Download the current version of each. Anything not published here is supplied on request, under NDA where appropriate.
Data Security Policy
The signed policy governing how data is handled, stored and protected.
PDF · 619 KBInformation Security Policy
The governing policy, with ownership and review cadence.
DOCX · 35 KBAcceptable Use Policy
What staff may and may not do with systems and data.
PDF · 75 KBIncident Response Plan
Preparation, detection, containment, eradication, recovery and follow-up.
DOCX · 22 KBPassword Policy
Complexity, rotation, reuse and lockout rules.
PDF · 74 KBBusiness Continuity Plan
Aligned with ISO 22301, with tested recovery objectives.
DOCX · 77 KBBYOD Policy
Controls for personal devices touching company systems.
DOCX · 15 KBIT Architecture
How the platform is put together.
PDF · 88 KBRetention Policy
How long data is held and how it is destroyed.
DOCX · 50 KBLegitimate Interest Assessment
The three-part balancing test behind our Article 6(1)(f) basis.
DOCX · 26 KBGDPR Compliance Brief
A client-facing summary for your legal team.
DOCX · 37 KBBribery, Corruption and Modern Slavery Brief
Our position and controls on each.
PDF · 99 KBSee also the sub-processor list, the Privacy Center, the Data Processing Addendum and the AI policy.
Start with the number.
Tell us the segment you actually sell to and we will send the exact count, the fill rates for that slice, and a sample — before anyone asks you for a budget.
