S-IT Application Engineering & Consulting team
IT leaders trust RedmineUP with their security

The highlight was the seamless migration from authentication via a locally hosted active directory to a OIDC-based Entra ID login through a custom RedmineUP plugin. Together with the support for custom domains, our users did basically not realize that there was a migration.

— Philip Müller, Head of Technology, S-IT Application Engineering & Consulting
Over 150 000 companies from 120 countries use RedmineUP plugins, themes and services
Intel
Bosch
Nintendo
IKEA
Cisco
Apple Inc.
China-Euro Vehicle Technology
NASA

Protecting your data

Data privacy

GDPR Compliant

GDPR-redmineup.png

Data storage

Certified to ISO

ISO_logo_blanc.png

Data encryption

SSL protected

ssl_security.png

Secure payments

PCI Compliant

PCI-redmineup.png

We are committed to ensuring the safety and security of your company’s data and to providing you with the information you need to understand and evaluate our security practices. You can verify that your company data remain secure and compliant.

Security FAQ

Is my data encrypted?

Yes. Data in transit is encrypted via TLS 1.2/1.3, and data at rest is encrypted using AES-256 across our AWS-hosted services.

Where is my data hosted?

On Amazon Web Services (AWS) infrastructure in Ireland (EU), which carries ISO/IEC 27001:2013 certification.

Do you support SSO and MFA?

Yes. We offer SAML-based Single Sign-On compatible with providers like Azure AD/Microsoft Entra ID, plus Multi-Factor Authentication available for all accounts.

How often are backups performed, and can I get a copy?

Backups run through two separate services (our own and AWS), both encrypted in transit and at rest. You can request an on-demand backup download at any time; each request is recorded in the audit log.

What's your uptime guarantee?

We guarantee 99.9% availability of the RedmineUP cloud service under our Service Level Agreement.

How do you handle security incidents?

We maintain a structured Incident Response Plan led by a designated Security Officer. Affected customers are notified promptly, kept updated on remediation, and receive a root cause analysis on resolution.

Are you GDPR compliant?

Yes. We comply with GDPR and other privacy laws, including data retention and secure deletion practices upon service termination.

Do you have independent security validation?

Yes. We are assessed by CyberVadis, an independent third-party security rating platform used by enterprise procurement teams to evaluate vendor risk. We scored 709/1000 overall (“Developed” rating, above the 641 benchmark average), including 1000/1000 for 3rd-Party Security Management, 834/1000 for Data Privacy, and 794/1000 for Business Continuity. We also rely on AWS's ISO/IEC 27001:2013 certification for our infrastructure and are evaluating additional certifications such as SOC 2.

How do you vet third-party vendors?

Sub-processors like AWS are bound by strict data protection agreements and assessed as part of our vendor risk management program. Our payment partner, 2Checkout, is PCI DSS v3.2 compliant.

Is my data isolated from other customers?

Yes. We use Kubernetes clusters to provide an independent, secure cluster for each client, ensuring logical segregation and isolation of data.

What happens to my data if I cancel my subscription?

Customer data is securely deleted in accordance with our data retention policies upon termination of service.

Who do I contact with a security question or concern?

Email support@redmineup.com — we respond to all requests within 24 hours.

Have more security questions?

Our security team is happy to walk through your vendor security review, share additional documentation, or answer specific questions about how we protect your data.