Security & connectivity
Security is not a visual promise.
It rests on the isolation of each boutique, on rights enforced in the database, and on limits described without exaggeration. This page summarises Rempart's security posture for the IT and security teams of counterparties.
The measures
What holds, and how.
- A separate instance per boutique
- Database, storage, domain and emails are separated. Two boutiques' documents never share the same database, so confidentiality between peers does not rest on a shared tenant identifier.
- Rights enforced in the database
- Critical rights are enforced by PostgreSQL row-level security, not only in the interface. A member reads only the folders and documents allowed for their role and group.
- Internal by default, published explicitly
- Any new document or folder is internal by default, then published explicitly. Members only see what is published and allowed for their audience.
- European hosting
- Documents, database and authentication are hosted in Ireland, in the European Union. The web application is delivered by Netlify on Amazon Web Services infrastructure.
- No external AI
- No document, excerpt, OCR output, chunk, embedding or prompt containing deal data is sent to a model provider.
- Watermark and audit log
- Watermark on supported formats; recorded views and downloads are logged and exportable. No web tool can prevent a photograph or a screenshot, and Rempart does not claim otherwise.
No ISO 27001 or SOC 2 certification is claimed. The first independent penetration test and the first real restore exercise are shown as planned, not done. See also the white-label data room page.
Book the free pilot
No credit card, reply within one business day