Trust Center

How Reliable Group Handles Your Data

This page is written for security, IT, compliance and diligence teams. It describes what Reliable Group can and cannot access, what we certify and what we do not, and which decisions belong to you.

Data handling

What we can and cannot access

In a standard GCC engagement

The team Reliable Group hires works inside your entity, on your systems, under your access controls. Reliable Group operates the local backbone (facilities, HR, payroll, statutory administration) and does not require access to your client data to do that work. Where an engagement does require access, the scope is defined in the services agreement rather than assumed.

In a Trace deployment

Capture runs on the machines your team designates and is limited to approved applications and windows. The record stays on the device in a local store inside your environment, with no captured content sent to any cloud service. Analysis runs inside your infrastructure. Access is restricted to named authorized personnel under the terms you agree, including Reliable Group personnel performing human validation inside your environment.

Certification posture

What we claim, and what we do not

Reliable Group does not hold SOC 2, ISO 27001 or CMMC certification, and HIPAA has no certification regime. What we provide instead is reviewable security architecture and data-handling documentation for your IT, security and compliance teams.

Reliable Group operates India centers under local labor and statutory requirements with documentation available for review. Control design for regulated client workloads is scoped per engagement with your compliance team.

We do not publish certification badges. A badge is a claim about an audit; where no audit exists, the honest artifact is the architecture itself.

Trace security architecture

How a Trace deployment is configured

Trace runs in-boundary: capture and analysis both take place inside your environment, and no captured content leaves it. The capture engine is broad by default, so what follows is the configuration Reliable Group applies and evidences before go-live. Your security team receives the configuration evidence, not just this description.

In-boundary by default

Pilot configuration

Capture and analysis both run inside your environment. No captured content leaves it, and there is no Reliable Group cloud in the path. Where no sufficiently capable in-boundary model exists for a given data set, that data set is not processed.

Scope limited by allow-list

Pilot configuration

Only named applications are recorded. Applications and windows outside the list are denied at source: an excluded window is never admitted to the capture stream by the operating system, so its content is not captured rather than captured and then filtered. Screen text is read from the accessibility tree, with optical character recognition only where no text layer exists.

What is switched off

Pilot configuration

Microphone and system audio are not captured. Keystroke capture is disabled, so application switch events are retained but the content of typing is not recorded. Clipboard contents are not captured. Product analytics and crash reporting are disabled and verified before go-live, so no telemetry leaves your environment.

Text-only retention

Pilot configuration

No screenshot frames are retained. Frames are used transiently to extract text where no accessibility text exists, then discarded. Storage is a local database with a full-text index and no media files. The data directory can be relocated to a volume your IT team approves, and file permissions on the store are restricted to the installing user and verified as an install step.

Local interface secured

Pilot configuration

The engine exposes a local interface on loopback that is unauthenticated in its default product configuration. Reliable Group enables authentication and disables network exposure. There are no inbound network connections in this configuration.

Named access, US persons only

Pilot configuration

Access to captured data and to the derived documentation is restricted to named authorized individuals who are US persons. Reliable Group offshore personnel do not have access to an engagement’s captured data. This applies to every Trace deployment, not only to regulated work.

Deterministic permissions

RG layer, in service

Requests through the local interface are restricted to specified applications, windows and content types, with raw-database and raw-frame endpoints denied at the interface layer. Enforcement is a deterministic policy in the request path rather than an instruction to a model. Direct file access to the store is governed separately by operating-system permissions. Administrators set policy centrally and do not see captured content.

Tamper-evident read log

RG layer, in service

Every read of captured data made through our analysis layer is recorded in an append-only, hash-chained log. It runs as a supervised service bound to loopback, and installation of the endpoint agent is gated on the log being live and its chain verifying. The chain is verifiable in a single command. Off-box export to a location the endpoint cannot write, such as your SIEM or write-once storage, is available as an option and is what makes the record durable against a root-level adversary on the endpoint.

No individual measurement, human validation

RG layer, in service

Outputs aggregate at task and procedure level. No individual is scored or ranked, whether observed or appearing incidentally. Generated documentation is reviewed and corrected by a person before it is treated as institutional knowledge.

What exclusion does not achieve

Exclusion operates at application and window level. It does not filter content that arrives inside an application that is in scope. If a mail client, chat client or browser is in scope, material arriving inside it is within capture even where the underlying repository is excluded. Scope minimization is therefore the primary control, and on-device removal of structured secrets sits behind it as one additional layer. That removal is early-stage, is validated against a seeded corpus before go-live with residual risk documented, and is not de-identification. If material outside the intended scope is found, capture pauses, the affected data is quarantined and destroyed with evidence, and the deployment does not resume until scope is corrected in writing.

What browser scoping does not achieve

Inside a permitted browser, scoping is applied by window title rather than by URL. A site whose page title does not contain the blocked term will not be excluded by that rule, and path-level exclusion within a site is not supported. Where a browser-reached system must be out of scope, the reliable options are to exclude it at the application or account level, or to exclude the browser entirely.

What the read log does not cover

The log records reads made through our analysis layer. It does not observe the capture pipeline itself, and it does not cover a user with local file access reading the on-device store directly. That path is governed by operating-system file permissions, which we restrict to the installing user and verify at install. Off-box export of the log is what makes it durable against a root-level adversary on the endpoint.

What encryption at rest does not cover

Encryption at rest is provided by platform full-disk encryption, configured with your IT team. Full-disk encryption protects data when the device is powered off and does not protect a running system. Where stronger protection is required, Reliable Group specifies application-level encryption as a deployment requirement rather than claiming it today.

Documentation

What your security team can review

The review package is three documents plus the evidence behind them. Confidential documents are released on request rather than published, so that what you receive is the version governing your deployment.

Technical Security Overview

Issued for reviewOn request, under NDA

Architecture, capture and storage methods, data handling, access control and oversight, with a status label on every control so you can tell what is in service today from what is completing before go-live.

Endpoint Agent Technical Fact Sheet

IssuedOn request, under NDA

The endpoint questions a security team asks before permitting an agent on managed devices: platform support, privileges, code signing, ports and network behavior, resource consumption, update and uninstall, provenance and software bill of materials.

Scope and Data Handling Agreement

Issued for signatureProvided with the engagement

In-scope and excluded systems, the notice position, purpose limitation, retention and destruction, and the quarantine procedure for material captured outside the intended scope.

Control-family alignment reference

MaintainedOn request

A NIST 800-171 control-family mapping, provided as an alignment reference. It is not a claim of assessed compliance, and Reliable Group does not assert its own CMMC certification.

Request the review package

Confidential documents are released under NDA to a named reviewer. Tell us your company, your role and which documents you need, and the request routes to a named owner at Reliable Group rather than a shared inbox.

Request documents

Open items are closed in a joint technical session against the specific release under review, including the software bill of materials, the current dependency vulnerability position, penetration-test scope and date, background-screening standard, and validation of on-device secret removal against a seeded corpus.

Deployment responsibilities

Decisions that belong to you

Some decisions cannot be delegated to an operating partner, and we do not pretend otherwise. In a Trace deployment or a GCC engagement, the following sit with the client:

  • The lawful basis for capture and the employee notice that accompanies it.
  • Which applications and windows are in scope, and which are excluded. Where a browser-reached system must be out of scope, that decision has to be made at the application or account level.
  • Retention periods, and who inside your organization may access the record.
  • The named internal owner accountable for the deployment.

Incidental third-party information is addressed through scope minimization, no retained screenshots, restricted access, limited retention, verified destruction and a quarantine procedure for material captured outside the intended scope.

Reporting

Security contact and disclosure

Report a vulnerability

Email a clear description, steps to reproduce and your contact details. We aim to acknowledge within two business days.

info@reliablegroup.com

Machine-readable policy

Our disclosure policy is published per RFC 9116 for automated discovery by security researchers and scanners.

/.well-known/security.txt

Reviewing Trace specifically? The control stack, scope limits and data path are described on the Trace page. Architecture and security documentation is available for review by your IT, security and compliance teams.

Bring your security team into the conversation early.

We would rather answer the hard questions before an engagement than after one.

400+ ClientsUS-HeadquarteredSince 19716 India Cities