Data Security Standards
IT leaders trust RedmineUP with their security
— Philip Müller, Head of Technology, S-IT Application Engineering & ConsultingThe highlight was the seamless migration from authentication via a locally hosted active directory to a OIDC-based Entra ID login through a custom RedmineUP plugin. Together with the support for custom domains, our users did basically not realize that there was a migration.
Over 150 000 companies from 120 countries use RedmineUP plugins, themes and services
Protecting your data
Data privacy
GDPR Compliant

Data storage
Certified to ISO

Data encryption
SSL protected

Secure payments
PCI Compliant

We are committed to ensuring the safety and security of your company’s data and to providing you with the information you need to understand and evaluate our security practices. You can verify that your company data remain secure and compliant.
Security FAQ
Is my data encrypted?
Yes. Data in transit is encrypted via TLS 1.2/1.3, and data at rest is encrypted using AES-256 across our AWS-hosted services.
Where is my data hosted?
On Amazon Web Services (AWS) infrastructure in Ireland (EU), which carries ISO/IEC 27001:2013 certification.
Do you support SSO and MFA?
Yes. We offer SAML-based Single Sign-On compatible with providers like Azure AD/Microsoft Entra ID, plus Multi-Factor Authentication available for all accounts.
How often are backups performed, and can I get a copy?
Backups run through two separate services (our own and AWS), both encrypted in transit and at rest. You can request an on-demand backup download at any time; each request is recorded in the audit log.
What's your uptime guarantee?
We guarantee 99.9% availability of the RedmineUP cloud service under our Service Level Agreement.
How do you handle security incidents?
We maintain a structured Incident Response Plan led by a designated Security Officer. Affected customers are notified promptly, kept updated on remediation, and receive a root cause analysis on resolution.
Are you GDPR compliant?
Yes. We comply with GDPR and other privacy laws, including data retention and secure deletion practices upon service termination.
Do you have independent security validation?
Yes. We are assessed by CyberVadis, an independent third-party security rating platform used by enterprise procurement teams to evaluate vendor risk. We scored 709/1000 overall (“Developed” rating, above the 641 benchmark average), including 1000/1000 for 3rd-Party Security Management, 834/1000 for Data Privacy, and 794/1000 for Business Continuity. We also rely on AWS's ISO/IEC 27001:2013 certification for our infrastructure and are evaluating additional certifications such as SOC 2.
How do you vet third-party vendors?
Sub-processors like AWS are bound by strict data protection agreements and assessed as part of our vendor risk management program. Our payment partner, 2Checkout, is PCI DSS v3.2 compliant.
Is my data isolated from other customers?
Yes. We use Kubernetes clusters to provide an independent, secure cluster for each client, ensuring logical segregation and isolation of data.
What happens to my data if I cancel my subscription?
Customer data is securely deleted in accordance with our data retention policies upon termination of service.
Who do I contact with a security question or concern?
Email support@redmineup.com — we respond to all requests within 24 hours.
Have more security questions?
Our security team is happy to walk through your vendor security review, share additional documentation, or answer specific questions about how we protect your data.







