THE DETAILS
Security
RedGem centralizes operational and business information from systems you choose to connect, so security is core to how we design and operate the platform. This page describes our current approach at a level intended to build trust without exposing sensitive implementation details.
Security at RedGem
Security shapes how RedGem is designed, from how organizations and stores are separated to how we handle credentials for connected services. As RedGem continues to develop, our security practices will continue to mature alongside it.
Access Control
RedGem is structured around organizations, stores, and users, with role-based access controls that govern what each user within an organization can see and do. Access to a given organization's data is scoped to authorized users within that organization.
Connected Services and OAuth
Where supported, RedGem uses OAuth-based authorization to connect to third-party services such as Shopify and Meta Ads. This allows you to grant RedGem access to a connected account without sharing your password with us directly, and you can revoke that access at any time from within RedGem or from the third-party service.
Protection of Sensitive Credentials
Sensitive credentials and tokens for connected third-party services are stored in encrypted form. Access to these credentials is restricted to the systems and processes that require them to operate the integration.
Data Isolation
RedGem is built to keep the operational data of different organizations separated from one another. Users within an organization access data according to the roles and permissions configured for that organization.
Application and Transport Security
Traffic to the RedGem platform is encrypted in transit using HTTPS/TLS. Access to the systems that operate RedGem is controlled and limited to what is required to run and support the platform.
Operational Security
RedGem maintains operational logging and tracks synchronization and integration jobs to support troubleshooting, reliability, and the detection of unexpected activity. We handle information obtained through connected services responsibly and only for the purpose of providing RedGem to you.
Customer Security Responsibilities
Security is a shared responsibility. You are responsible for safeguarding your RedGem account credentials, for managing which users and roles have access within your organization, and for only connecting stores, ad accounts, mailboxes, or other systems you are authorized to connect.
Reporting a Security Issue
If you believe you have found a security issue affecting RedGem, please report it to security@getredgem.com. Please include enough detail for us to reproduce and understand the issue.
For your safety, do not send passwords, API secrets, private keys, recovery codes, authentication tokens, or other full credentials by ordinary email — including when reporting a security issue.