We're a small, veteran-run shop — not a Fortune 500 with a compliance department. Here's exactly what that means for your data, in plain language, with nothing claimed that isn't actually true today.
Your connection to rucktech.net is encrypted end-to-end (TLS/SSL) — nothing you send us, including anything typed into a form, travels in plain text.
Payments are processed by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of card-data security certification that exists. Your card details go straight to Stripe and never touch RuckTech's servers.
Client records live behind row-level security rules at the database layer — not just an app-level check. A client account can only ever read its own proposals, documents, and requests; there is no shared table a bug could accidentally expose.
Contracts and onboarding paperwork are delivered through signed links that expire — never a permanent public URL anyone with the link could reuse indefinitely.
Account sign-in is handled by our authentication provider using industry-standard hashing — RuckTech staff cannot see, recover, or reset it to a known value; a lost password can only be reset via a one-time email link.
Administrative functions (viewing all clients, issuing discounts, managing documents) require a staff role on the account — a client login has no path to that data or those actions, by design, not just by hiding a button.
RuckTech's SDVOSB (Service-Disabled Veteran-Owned Small Business) certification is in progress through the SBA. We don't hold a SOC 2 report or a formal cyber-insurance policy yet, and we'll say so plainly if asked rather than imply otherwise — we'd rather tell you exactly where we stand than dress up a badge that doesn't mean anything yet.
Questions about how we handle a specific piece of information? Email brucerucker@rucktech.net — see also our Privacy Policy.