Security
High-level information about the controls used to protect Rinaldi Services LLC accounts and business operations.
Account Protection
Rinaldi Services LLC supports multi-factor authentication, account security checks, device/session management, password controls, and administrative recovery procedures. Sensitive security tokens and provider keys are intended to remain server-side rather than being embedded in public website code.
Authorization & Data Access
Authenticated website data is protected through application authorization and Supabase/PostgreSQL row-level security policies. Staff capabilities are permission-based so operational, security, agreement, payment, and compliance functions can be limited to appropriate roles.
Session & Device Controls
Current account-security features include device tracking, trusted-device controls after MFA verification, local sign-out, sign-out of other sessions, and account-wide sign-out/reset controls when the required backend migration is installed.
Operational Security
Security and compliance records are separated from customer-facing data. Internal tools support incident records, vendor reviews, retention reviews, workflow tasks and audit history. These registers are not published to customers unless a specific disclosure is intentionally placed in the public vendor register.
Report a Security Concern
Do not send passwords, MFA codes, private keys, or other authentication secrets. Report a suspected website security concern through the Contact page or email contact@rinaldiservices.com. For sign-in or account-security issues, email accounts@rinaldiservices.com.