How Reliable Group Handles Your Data
This page is written for security, IT, compliance and diligence teams. It describes what Reliable Group can and cannot access, what we certify and what we do not, and which decisions belong to you.
What we can and cannot access
In a standard GCC engagement
The team Reliable Group hires works inside your entity, on your systems, under your access controls. Reliable Group operates the local backbone (facilities, HR, payroll, statutory administration) and does not require access to your client data to do that work. Where an engagement does require access, the scope is defined in the services agreement rather than assumed.
In a Trace deployment
Capture runs on the machines your team designates and is limited to approved applications and windows. The record stays on the device in a local store inside your environment, with no captured content sent to any cloud service. Analysis runs inside your infrastructure. Access is restricted to named authorized personnel under the terms you agree, including Reliable Group personnel performing human validation inside your environment.
What we claim, and what we do not
Reliable Group does not hold SOC 2, ISO 27001 or CMMC certification, and HIPAA has no certification regime. What we provide instead is reviewable security architecture and data-handling documentation for your IT, security and compliance teams.
Reliable Group operates India centers under local labor and statutory requirements with documentation available for review. Control design for regulated client workloads is scoped per engagement with your compliance team.
We do not publish certification badges. A badge is a claim about an audit; where no audit exists, the honest artifact is the architecture itself.
How a Trace deployment is configured
Trace runs in-boundary: capture and analysis both take place inside your environment, and no captured content leaves it. The capture engine is broad by default, so what follows is the configuration Reliable Group applies and evidences before go-live. Your security team receives the configuration evidence, not just this description.
In-boundary by default
Pilot configurationCapture and analysis both run inside your environment. No captured content leaves it, and there is no Reliable Group cloud in the path. Where no sufficiently capable in-boundary model exists for a given data set, that data set is not processed.
Scope limited by allow-list
Pilot configurationOnly named applications are recorded. Applications and windows outside the list are denied at source: an excluded window is never admitted to the capture stream by the operating system, so its content is not captured rather than captured and then filtered. Screen text is read from the accessibility tree, with optical character recognition only where no text layer exists.
What is switched off
Pilot configurationMicrophone and system audio are not captured. Keystroke capture is disabled, so application switch events are retained but the content of typing is not recorded. Clipboard contents are not captured. Product analytics and crash reporting are disabled and verified before go-live, so no telemetry leaves your environment.
Text-only retention
Pilot configurationNo screenshot frames are retained. Frames are used transiently to extract text where no accessibility text exists, then discarded. Storage is a local database with a full-text index and no media files. The data directory can be relocated to a volume your IT team approves, and file permissions on the store are restricted to the installing user and verified as an install step.
Local interface secured
Pilot configurationThe engine exposes a local interface on loopback that is unauthenticated in its default product configuration. Reliable Group enables authentication and disables network exposure. There are no inbound network connections in this configuration.
Named access, US persons only
Pilot configurationAccess to captured data and to the derived documentation is restricted to named authorized individuals who are US persons. Reliable Group offshore personnel do not have access to an engagement’s captured data. This applies to every Trace deployment, not only to regulated work.
Deterministic permissions
RG layer, in serviceRequests through the local interface are restricted to specified applications, windows and content types, with raw-database and raw-frame endpoints denied at the interface layer. Enforcement is a deterministic policy in the request path rather than an instruction to a model. Direct file access to the store is governed separately by operating-system permissions. Administrators set policy centrally and do not see captured content.
Tamper-evident read log
RG layer, in serviceEvery read of captured data made through our analysis layer is recorded in an append-only, hash-chained log. It runs as a supervised service bound to loopback, and installation of the endpoint agent is gated on the log being live and its chain verifying. The chain is verifiable in a single command. Off-box export to a location the endpoint cannot write, such as your SIEM or write-once storage, is available as an option and is what makes the record durable against a root-level adversary on the endpoint.
No individual measurement, human validation
RG layer, in serviceOutputs aggregate at task and procedure level. No individual is scored or ranked, whether observed or appearing incidentally. Generated documentation is reviewed and corrected by a person before it is treated as institutional knowledge.
What exclusion does not achieve
Exclusion operates at application and window level. It does not filter content that arrives inside an application that is in scope. If a mail client, chat client or browser is in scope, material arriving inside it is within capture even where the underlying repository is excluded. Scope minimization is therefore the primary control, and on-device removal of structured secrets sits behind it as one additional layer. That removal is early-stage, is validated against a seeded corpus before go-live with residual risk documented, and is not de-identification. If material outside the intended scope is found, capture pauses, the affected data is quarantined and destroyed with evidence, and the deployment does not resume until scope is corrected in writing.
What browser scoping does not achieve
Inside a permitted browser, scoping is applied by window title rather than by URL. A site whose page title does not contain the blocked term will not be excluded by that rule, and path-level exclusion within a site is not supported. Where a browser-reached system must be out of scope, the reliable options are to exclude it at the application or account level, or to exclude the browser entirely.
What the read log does not cover
The log records reads made through our analysis layer. It does not observe the capture pipeline itself, and it does not cover a user with local file access reading the on-device store directly. That path is governed by operating-system file permissions, which we restrict to the installing user and verify at install. Off-box export of the log is what makes it durable against a root-level adversary on the endpoint.
What encryption at rest does not cover
Encryption at rest is provided by platform full-disk encryption, configured with your IT team. Full-disk encryption protects data when the device is powered off and does not protect a running system. Where stronger protection is required, Reliable Group specifies application-level encryption as a deployment requirement rather than claiming it today.
What your security team can review
The review package is three documents plus the evidence behind them. Confidential documents are released on request rather than published, so that what you receive is the version governing your deployment.
Technical Security Overview
Issued for reviewOn request, under NDAArchitecture, capture and storage methods, data handling, access control and oversight, with a status label on every control so you can tell what is in service today from what is completing before go-live.
Endpoint Agent Technical Fact Sheet
IssuedOn request, under NDAThe endpoint questions a security team asks before permitting an agent on managed devices: platform support, privileges, code signing, ports and network behavior, resource consumption, update and uninstall, provenance and software bill of materials.
Scope and Data Handling Agreement
Issued for signatureProvided with the engagementIn-scope and excluded systems, the notice position, purpose limitation, retention and destruction, and the quarantine procedure for material captured outside the intended scope.
Control-family alignment reference
MaintainedOn requestA NIST 800-171 control-family mapping, provided as an alignment reference. It is not a claim of assessed compliance, and Reliable Group does not assert its own CMMC certification.
Request the review package
Confidential documents are released under NDA to a named reviewer. Tell us your company, your role and which documents you need, and the request routes to a named owner at Reliable Group rather than a shared inbox.
Request documentsOpen items are closed in a joint technical session against the specific release under review, including the software bill of materials, the current dependency vulnerability position, penetration-test scope and date, background-screening standard, and validation of on-device secret removal against a seeded corpus.
Decisions that belong to you
Some decisions cannot be delegated to an operating partner, and we do not pretend otherwise. In a Trace deployment or a GCC engagement, the following sit with the client:
- The lawful basis for capture and the employee notice that accompanies it.
- Which applications and windows are in scope, and which are excluded. Where a browser-reached system must be out of scope, that decision has to be made at the application or account level.
- Retention periods, and who inside your organization may access the record.
- The named internal owner accountable for the deployment.
Incidental third-party information is addressed through scope minimization, no retained screenshots, restricted access, limited retention, verified destruction and a quarantine procedure for material captured outside the intended scope.
Security contact and disclosure
Report a vulnerability
Email a clear description, steps to reproduce and your contact details. We aim to acknowledge within two business days.
info@reliablegroup.comMachine-readable policy
Our disclosure policy is published per RFC 9116 for automated discovery by security researchers and scanners.
/.well-known/security.txtReviewing Trace specifically? The control stack, scope limits and data path are described on the Trace page. Architecture and security documentation is available for review by your IT, security and compliance teams.
Bring your security team into the conversation early.
We would rather answer the hard questions before an engagement than after one.