THE DETAILS

Security

RedGem centralizes operational and business information from systems you choose to connect, so security is core to how we design and operate the platform. This page describes our current approach at a level intended to build trust without exposing sensitive implementation details.

Security at RedGem

Security shapes how RedGem is designed, from how organizations and stores are separated to how we handle credentials for connected services. As RedGem continues to develop, our security practices will continue to mature alongside it.

Access Control

RedGem is structured around organizations, stores, and users, with role-based access controls that govern what each user within an organization can see and do. Access to a given organization's data is scoped to authorized users within that organization.

Connected Services and OAuth

Where supported, RedGem uses OAuth-based authorization to connect to third-party services such as Shopify and Meta Ads. This allows you to grant RedGem access to a connected account without sharing your password with us directly, and you can revoke that access at any time from within RedGem or from the third-party service.

Protection of Sensitive Credentials

Sensitive credentials and tokens for connected third-party services are stored in encrypted form. Access to these credentials is restricted to the systems and processes that require them to operate the integration.

Data Isolation

RedGem is built to keep the operational data of different organizations separated from one another. Users within an organization access data according to the roles and permissions configured for that organization.

Application and Transport Security

Traffic to the RedGem platform is encrypted in transit using HTTPS/TLS. Access to the systems that operate RedGem is controlled and limited to what is required to run and support the platform.

Operational Security

RedGem maintains operational logging and tracks synchronization and integration jobs to support troubleshooting, reliability, and the detection of unexpected activity. We handle information obtained through connected services responsibly and only for the purpose of providing RedGem to you.

Customer Security Responsibilities

Security is a shared responsibility. You are responsible for safeguarding your RedGem account credentials, for managing which users and roles have access within your organization, and for only connecting stores, ad accounts, mailboxes, or other systems you are authorized to connect.

Reporting a Security Issue

If you believe you have found a security issue affecting RedGem, please report it to security@getredgem.com. Please include enough detail for us to reproduce and understand the issue.

For your safety, do not send passwords, API secrets, private keys, recovery codes, authentication tokens, or other full credentials by ordinary email — including when reporting a security issue.