RubberfitREV · 2026.05
See pricing →
Security

Strong posture. Honest about what we are.

Rubberfit runs the technical controls a SOC 2 auditor would expect — RLS at the database, six-role RBAC enforced twice, audit log with before/after JSONB snapshots, signed-URL document sharing, encryption at rest. We are not SOC 2 certified yet; the full unvarnished posture and roadmap live in the docs.

Defense in depth4 LAYERS · DB-ENFORCED
BROWSER · TLS 1.3RBAC · 6 ROLESRLS · POSTGRES POLICIESENCRYPTED AT RESTREQUEST · JWTROW-LEVEL SECURITY · 12+ TABLES
A · What's shipped today

Four headlines. Full inventory in the docs.

The technical controls, the gaps, and the SOC 2 roadmap each get their own page in the docs site — including the parts that don't pass a security questionnaire today.

01· Live

Row-level security on every table

Postgres RLS policies on every customer-facing table. No app-layer bypass.

02· Live

Six-role RBAC, enforced twice

Middleware + RLS policies. Either layer alone is sufficient.

03· Live

Admin audit log

Before/after JSONB snapshots, IP, user agent. Field-level changes captured.

04· Live

Signed-URL document sharing

Customer PDFs share via signed URLs, not public-by-default access.

The full read · docs.rubberfit.app

Three pages. One honest write-up.

The full security posture, the SOC 2 roadmap, and the data-handling specifics — including what is not yet shipped — live on the docs site so a security questionnaire can paste a single URL into the response field.

Read the full postureSOC 2 roadmap

Got a questionnaire? Email security@rubberfit.app

Ready when you are

See the price. Start a trial.

Per-seat pricing. 14-day free trial, no credit card. Run real cuts against your own stock — if it doesn't pay for itself the first week, walk.

See pricing