(888) 278-3433contact@rampedup.io
Count build — August 2026Opt outLog in
RampedUp
Sign Up for Free

Trust

Data security

RampedUp manages large-scale contact and company data, and data security is a core priority. Data is encrypted with AES-256 via AWS KMS at rest and TLS 1.2 in transit, access is role-based and least-privilege, and a formal incident response plan is in place. RampedUp reported no personal data breaches in the prior three years.

Every policy behind this page is downloadable. Jump to the Security Documentation Library →

Policy framework

RampedUp manages large-scale contact and company data, and data security is a core priority. We maintain formal, documented information security policies and procedures that are approved by senior management, communicated to staff and available for reference, assigned clear ownership and responsibilities, enforced with disciplinary provisions for non-compliance, and reviewed periodically for continued relevance.

Employees acknowledge codes of conduct and confidentiality obligations. Vendor risk assessments and supporting policies are maintained, including a 23-point vendor risk assessment for key suppliers.

Infrastructure, hosting and third parties

RampedUp is hosted on Amazon Web Services. Backups use AWS Key Management Service (KMS) with AES-256 encryption, and AWS Backup with automatic redundancy restoration.

Third-party and sub-processor review is a structured process. The sub-processor list is published publicly.

Data protection and encryption

Data in transit is protected with TLS 1.2. Data at rest uses industry-standard strong encryption, including AES-256 via AWS KMS.

On account expiration or closure, data is removed by cryptographic erasure. Administrators hold deletion permissions, with secure procedures at contract end.

Access control and authorized users

Only formally authorized users may access RampedUp systems, each with a unique user identity. RampedUp employees do not have access to customer passwords.

Access is role-based across System Administration, Instance Administration and User roles, designed around least-privilege access.

Password policy

Strong passwords are required: at least 12 characters with a mix of upper and lowercase letters, numbers and special characters. Passwords change every 90 days, the last five passwords cannot be reused, and ten failed login attempts trigger a lockout.

Violations can result in loss of access, disciplinary action, or legal consequences.

Retention and deletion

Undefined datasets are not republished after a set period — 15 months, for example. Data minimization is applied as a principle, and data is deleted by cryptographic erasure at contract end.

RampedUp does not source data from sites targeted at minors.

Monitoring, logging and incident response

A formal Incident Response Plan covers preparation through follow-up. AWS CloudTrail and VPC Flow Logs provide logging, with monitoring logs retained for approximately 30 to 90 days. Systems can be isolated through security group changes.

Breach notification and history

Affected customers are notified within 72 hours of breach awareness, aligned with GDPR. Impacted persons are notified within 14 business days.

RampedUp reported no personal data breaches in the prior three years.

Business continuity and disaster recovery

The business continuity management system is aligned with ISO 22301 — aligned, but not formally certified. Documented business continuity and disaster recovery procedures are tested periodically.

Critical data is backed up offsite through AWS Backup with encrypted, redundant storage, against clear recovery objectives with regular testing.

Governance, training and compliance

Security and privacy awareness training is provided to key staff. RampedUp complies with applicable local privacy laws inside and outside the United States, including EU and UK data protection law and US state privacy laws such as CCPA/CPRA, and maintains a Data Protection Officer function.

The AWS SOC 3 Security, Availability, Confidentiality and Privacy report is publicly available documentation.

RampedUp cloud hosting: AWS certifications

RampedUp runs on AWS, so AWS’s own certifications are part of our control environment. Both are independently audited and published by AWS.

ISO 27001:2022 certification for AWS

The certification provides a systematic approach to managing sensitive company information through a comprehensive framework of policies and procedures. The standard encompasses an organization’s people, processes, and IT systems, and directs the implementation of a strong risk management process. ISO 27001:2022, the latest version, introduces significant changes that include the restructuring of control categories and the addition of new controls focusing on threat intelligence and cloud security.

Key aspects of AWS physical and environmental controls — each links to that control in the AWS Trust Center:

SOC 3

AWS System and Organization Controls (SOC) Reports are independent third-party examination reports that demonstrate how AWS achieves key compliance controls and objectives. The purpose of these reports is to help you and your auditors understand the AWS controls established to support operations and compliance.

AWS SOC 3 Security, Availability, Confidentiality & Privacy Report

Both documents are published and maintained by AWS, so the links above always resolve to the current version rather than a copy we host.

Data broker registrations

Registered where registration is required, with the numbers so you can verify us independently.

RampedUp participates in the California Delete Request and Opt-out Platform (DROP), a centralized tool allowing California residents to submit a single request to have their personal data removed from hundreds of registered data brokers. Removal requests from any jurisdiction are honored through the do-not-sell portal; once confirmed, the person is removed from the database and every customer who downloaded that record is notified.

Security Documentation Library

Download the current version of each. Anything not published here is supplied on request, under NDA where appropriate.

See also the sub-processor list, the Privacy Center, the Data Processing Addendum and the AI policy.

Start with the number.

Tell us the segment you actually sell to and we will send the exact count, the fill rates for that slice, and a sample — before anyone asks you for a budget.

Request a custom count Browse published counts