RMOZ / trust

Security and governance

A control framework for identity, permissions, key custody, data handling, resilience and accountable operations.

Set the assurance boundary

Security is designed into every RMOZ implementation and documented for each client. Security documentation and assurance evidence are shared with clients and procurement teams under confidentiality.

Assign access and key responsibilities

Each design specifies least-privilege roles, privileged approvals, key ownership, rotation and recovery. It defines who can deploy changes, access source evidence and revoke an issuer, and separation of duties is tested before go-live.

Validate sovereignty and data handling

Each implementation defines hosting jurisdiction, cross-border data flows, administrator location, encryption responsibilities, backup access and supplier exit arrangements. Deployments can be hosted within the Kingdom where required.

Plan incidents, continuity and correction

Incident reporting routes, decision authority, recovery objectives and evidence preservation are agreed before operation. Compromised keys, incorrect records and unavailable dependencies are rehearsed, and commitments are documented in each service agreement.

FAQ

Questions, answered

How is security assured?

Through secure design, least-privilege access, key management, independent security review and tested recovery for each implementation. Assurance documentation is shared with clients.

Does an immutable ledger make an application secure?

No. Security depends on the whole system: keys, permissions, input data, integrations and governance. RMOZ designs each of these explicitly.

How do I report a security issue?

Email [email protected] with the subject “Security” and a short description. Please do not include exploit code, credentials or sensitive records in your first message; we will reply with a secure channel.