HomeCyberSecurityAccessibility

Legal & Compliance

Ripplemesh Data Security Policy

Our commitment to protecting your data, maintaining your privacy, and operating with transparency across every layer of the Ripplemesh platform.

Effective Date: May 28, 2026·Ripplemesh Corporation, Austin, Texas·admin@ripplemesh.com

Notice: This policy is provided for informational purposes. It does not constitute legal advice. For specific legal questions regarding data privacy, please consult qualified legal counsel.

Introduction

Ripplemesh Corporation ("Ripplemesh," "we," "us," or "our") is committed to the highest standards of data security, information protection, and user privacy. We understand that the operational data entrusted to our platform by industrial organizations is mission-critical, often sensitive, and subject to stringent regulatory requirements. Protecting that data is not merely a compliance obligation — it is a foundational architectural commitment.

This Data Security Policy describes the types of information Ripplemesh collects, how we protect it, how we use it, and the rights you hold as a data subject. It applies to all users of the Ripplemesh platform, including employees of our customers, partners, and all individuals who interact with our services.

Our AI-native platform is purpose-built for industrial operations — oil and gas, utilities, manufacturing, and regulated industries — where data integrity is inseparable from operational safety. Every security measure described in this policy is implemented with that operational reality in mind.

ISO 27001

Information security management alignment

SOC 2 Type II

Third-party security and availability controls

GDPR Ready

Privacy-by-design data handling practices

Information We Collect

We collect only what is necessary to deliver, maintain, and improve the Ripplemesh platform.

Ripplemesh collects several categories of data, each serving a defined and documented purpose. We do not collect data speculatively or beyond what is required to provide our services.

User Account Information

  • ·Full name and email address — for authentication, access control, and communications
  • ·Job title, department, and organizational role — for role-based access control (RBAC) and personalized experience delivery
  • ·Login timestamps and session metadata — for security auditing and account protection

Operational Data

  • ·Shift logs, permit records, incident reports, and compliance entries — the core operational record generated through platform workflows
  • ·Training completion records, competency assessments, and certification data — for workforce intelligence and ISO/TS 30437 compliance
  • ·Observation and behavioral data captured through experience statements — for Kirkpatrick Level 3 analytics and command stability monitoring

Usage & Behavioral Data

  • ·Feature utilization patterns — to identify areas for platform improvement and user experience optimization
  • ·Query patterns and report access logs — for performance tuning and audit trail integrity
  • ·Device type, browser, and general geographic region — for security anomaly detection

Technical & Metadata

  • ·API call logs and integration event records — for system reliability and debugging
  • ·Error logs and diagnostic data — for platform stability and quality assurance
  • ·Aggregated performance metrics — for capacity planning and infrastructure optimization

How We Protect Your Information

Defense in depth — security at every layer of the Ripplemesh architecture.

Ripplemesh applies a defense-in-depth security model that addresses data protection at the infrastructure, application, and operational levels. The following measures are in effect across all production environments.

Encryption at Rest and in Transit

All data stored within the Ripplemesh platform is encrypted at rest using AES-256 encryption. All data transmitted between clients and Ripplemesh infrastructure is encrypted in transit using TLS 1.2 or higher. This applies to all API communications, file transfers, and session data without exception.

Role-Based Access Control (RBAC)

Access to data is governed by a granular RBAC model that enforces the principle of least privilege. Users can only access the data, workflows, and AI agents appropriate to their defined organizational role. RBAC is enforced at both the application layer and the database layer through row-level security (RLS) policies.

Row-Level Security (RLS)

Ripplemesh's multi-tenant architecture enforces strict data isolation at the database level. Each organization's data is logically separated and cannot be accessed by users of other tenant organizations. RLS policies are applied to every data query — no query can return data outside the authenticated user's authorized scope.

AI Data Isolation

All AI inference operations on the Ripplemesh platform are executed via secure, server-side backend functions. User data is never sent to third-party AI providers in an uncontrolled manner. Ripplemesh does not use customer operational data to train or fine-tune AI models. AI outputs are grounded exclusively in verified organizational data, not in generative speculation.

Regular Security Audits and Penetration Testing

Ripplemesh undergoes regular third-party security assessments, including penetration testing and vulnerability scanning. Identified vulnerabilities are triaged and remediated according to a severity-based response protocol. Results inform ongoing security roadmap priorities.

Secure Development Practices

Our engineering team follows secure development lifecycle (SDL) principles, including code review requirements, dependency vulnerability scanning, secrets management through environment-isolated vaults, and mandatory security training. No credentials or secrets are stored in application code.

ISO 27001 Alignment

Ripplemesh's information security management practices are aligned with the ISO/IEC 27001 standard, providing a systematic framework for managing information security risks across people, processes, and technology. This alignment ensures that data protection is a managed, measurable, and continuously improved organizational function.

How We Use Your Information

Data is used to serve you — never to profile you for resale.

Ripplemesh does not sell, rent, or trade user data to any third party. Your operational data belongs to your organization. We use it only to provide, maintain, and improve the services you have engaged us to deliver.

  • Service Delivery: To authenticate users, enforce access permissions, execute AI agent workflows, and deliver the operational intelligence capabilities of the platform.
  • Operational Insights: To generate workforce intelligence reports, Kirkpatrick Level 3 behavioral analytics, compliance dashboards, and command stability monitoring as defined by your organizational configuration.
  • Platform Improvement: Aggregated and anonymized usage data is analyzed to identify performance improvements, prioritize feature development, and resolve stability issues.
  • Personalized Experience: Role and preference data is used to surface relevant content, reports, and agent interactions appropriate to each user's function.
  • Compliance and Audit Support: Operational records are maintained to support your organization's compliance obligations under OSHA, BSEE, EPA RMP, ISO standards, and other applicable regulatory frameworks.
  • Security and Fraud Prevention: Login and activity data is used to detect anomalous access patterns, prevent unauthorized access, and protect account integrity.
  • Communications: Account-related notifications, platform updates, and security alerts are delivered to registered email addresses. Marketing communications are sent only with explicit consent and include opt-out mechanisms.

Data Sharing and Disclosure

We share only what is necessary, with parties bound by appropriate protections.

Ripplemesh does not disclose your personal or operational data except in the limited circumstances described below. In all cases, data sharing is governed by contractual safeguards and the principle of minimum necessary disclosure.

Trusted Service Providers

Ripplemesh works with a limited set of infrastructure and technology service providers (e.g., cloud hosting providers, security monitoring services) who may process data on our behalf. These providers are bound by Data Processing Agreements (DPAs) that restrict their use of your data to the specific services they provide to Ripplemesh.

Legal and Regulatory Requirements

We may disclose data when required to do so by applicable law, court order, or regulatory authority — such as responses to valid subpoenas, government investigations, or regulatory compliance inquiries. We will notify affected customers of such requests where legally permitted.

Organizational Administrators

Your organization's designated Ripplemesh administrators may have access to user records within your tenant as necessary to manage the platform, configure access controls, and maintain compliance. This is governed by your organization's own data governance policies.

Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all Ripplemesh assets, user data may be transferred as part of that transaction. Affected customers will be notified in advance, and any successor entity will be bound by the terms of this policy.

With Your Consent

We may share data in other circumstances with your explicit prior consent. We will always identify the purpose and recipient before requesting such consent.

Data Retention

We retain data for as long as necessary — and not a day longer.

Ripplemesh retains user data for the period necessary to provide contracted services and to meet applicable legal, regulatory, and audit obligations. Our retention practices are as follows:

  • Active Account Data: User account information, operational records, and platform data are retained for the duration of the active service agreement between Ripplemesh and your organization.
  • Post-Termination Retention: Following contract termination, data is retained for a transition period not to exceed 90 days to facilitate data export and handover. After this period, data is securely and irreversibly deleted from production systems.
  • Legal and Regulatory Obligations: Certain records may be retained beyond the standard retention period where required by applicable law (e.g., OSHA recordkeeping requirements, financial audit obligations). Such retention is documented and time-bounded.
  • Backup and Disaster Recovery: Data may persist in encrypted backup systems for up to 30 days beyond the active deletion date, after which it is purged from backup archives.
  • Anonymized Aggregates: Aggregated, de-identified performance and usage data may be retained indefinitely for platform improvement and benchmarking purposes, as this data cannot be linked to any individual or organization.

Your Rights Regarding Your Data

We are committed to honoring your privacy rights promptly and transparently.

Depending on your jurisdiction, you may hold the following rights with respect to your personal data held by Ripplemesh. We are committed to honoring these rights within the timeframes required by applicable law (typically 30 days of receipt of a verified request).

Right of Access

Request a copy of the personal data we hold about you and information about how it is processed.

Right of Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right of Erasure

Request deletion of your personal data where there is no compelling legal basis for its continued processing.

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances while a dispute is resolved.

Right to Data Portability

Request your personal data in a structured, machine-readable format for transfer to another service provider.

Right to Object

Object to processing of your personal data for certain purposes, including direct marketing.

How to Exercise Your Rights

To exercise any of the rights described above, submit a written request to admin@ripplemesh.com with the subject line "Data Privacy Request." Include your full name, email address, organization, and a description of the right you wish to exercise. We will verify your identity before processing the request and respond within 30 days.

Changes to This Policy

We will always tell you when the rules change.

Ripplemesh reserves the right to update this Data Security Policy periodically to reflect changes in our practices, applicable law, or platform capabilities. We are committed to transparent communication when such changes occur.

  • Material Changes: For changes that significantly affect how your data is collected, used, or shared, we will provide at least 30 days' advance notice via email to registered account holders and a prominent notice within the Ripplemesh platform.
  • Minor Changes: For non-material updates (e.g., clarifications, corrections, formatting changes), we will update the effective date at the top of this policy without separate notification.
  • Continued Use: Your continued use of the Ripplemesh platform following the effective date of any updated policy constitutes your acknowledgment of the changes. If you do not agree with the updated policy, you should discontinue use and contact us to arrange data export and account closure.
  • Archived Versions: Previous versions of this policy are available upon request by contacting admin@ripplemesh.com.

Contact Us

Privacy questions deserve prompt, human answers.

If you have questions, concerns, or requests related to this Data Security Policy or Ripplemesh's handling of your personal or operational data, please contact us through any of the following channels. We are committed to responding to all privacy inquiries within five business days.

Privacy & Data Security

Ripplemesh Corporation

Austin, Texas, United States

admin@ripplemesh.com

Subject: Data Privacy Request

Questions about our security architecture?

Our team is available to walk you through how Ripplemesh protects your operational data in detail.

Request a Security Briefing