Questions and Answers on Security

The following questions and answers provide a concise reference for the most frequently asked security and data-related inquiries from our customers. During procurement processes and security assessments, our cloud specialists are available to support detailed questionnaires and in-depth discussions.


Where does RD8 store data? 

All customer data is hosted on Google Cloud Platform (GCP) servers in Belgium. All stored files and databases are encrypted at rest using AES-256-GCM encryption with Google-managed cryptographic keys.


How often does RD8 take backups? 

Automated data backups are performed daily (every 24 hours).

 

Are RD8 prepared to restore from backups? 

Yes. Relevant technical personnel are trained in backup restoration procedures, and disaster recovery (DR) restoration drills are conducted at least annually to validate data integrity and recovery timelines.


How long are backups stored before deletion? 

Database backups are retained for 30 days, and file storage backups are retained for 14 days prior to automated deletion.


How can users authenticate? 

Users can authenticate using standard username and password credentials or via Single Sign-On (SSO) managed through Auth0, allowing integration with enterprise identity providers such as Microsoft Entra ID (Azure AD).


How do RD8 manage access to cloud infrastructure? 

Access to cloud infrastructure is restricted to authorized RD8 personnel following the principle of least privilege.

Administrative accounts and elevated privileges are strictly separated from day-to-day user accounts, and multi-factor authentication (MFA) is required across all access points. 

All infrastructure changes are version-controlled, peer-reviewed, and deployed automatically via CI/CD pipelines.


How do Rd8 secure data transfer over the public internet? 

All public APIs enforce HTTPS with TLS 1.2 or higher and restrict cipher suites to secure algorithms, specifically ChaCha20 and AES-GCM, in accordance with our Cryptography Policy.

 

How do RD8 manage application releases? 

Application releases are strictly managed. Code changes must pass mandatory peer review and quality assurance testing before deployment by authorized personnel. 

All releases are version-controlled and tagged, with detailed audit logs recording who deployed what code, when, and to which environment.


Do RD8 developers get proper security training? 

Yes. All developers complete role-specific secure development training bi-annually and are required to follow RD8’s secure code review checklist during mandatory peer code reviews.


Last updated May 1st. 2026 by Chief Cloud Operations Officer

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article