---
title: Security built into every environment
description: "Every Core environment has security management built in: alerts on sensitive changes, audit logs, roles and permissions, IP bans and encryption at rest."
url: "https://rual.nl/en/security"
locale: en
alternate: "https://rual.nl/security"
updated: 2026-08-03
source: "https://rual.nl"
---

# Security is not a module. It is built into every environment.

Every Core environment watches itself: who can get in, what changes and whether anything looks off. You do not have to switch anything on, and you see all of it.

[Book a demo](https://rual.nl/en/demo)

[About our hosting](https://rual.nl/en/hosting)

**Security alerts** — sample data

- Signed in from a new IP address

- Two-factor setting changed

- Sign-in attempts blocked after 5 failures (held for review)

## What every environment does by default

No settings you can forget to switch on. This is active from day one.

- **You hear about it straight away** — Core emails you automatically when something sensitive happens to your account: a sign-in from a new location, a change to your two-factor settings or a new password.

- **Everything traceable** — Sensitive administrative actions are recorded in an audit log kept for 7 years, accessible only with the right permissions. Request logs are kept for 2 weeks by default, configurable per environment.

- **Access that fits the job** — Roles and permissions per user, with two-factor authentication through an authenticator app (TOTP) or SMS. People see only what their work requires.

- **Attacks stop themselves** — Five failed sign-in attempts trigger a temporary lockout, and persistent attempts an IP ban. Requests carrying attack signatures (injection, scanners, probes) earn an immediate 30-day ban. Trusted IP addresses go on an allowlist.

- **Encrypted, always** — All data is encrypted at rest. Files and fields are encrypted with AES up to 256-bit, passwords are hashed with PBKDF2-SHA512 at 200,000 iterations. The full cluster is backed up every hour to separate storage.

- **Updates without gaps** — Security patches are rolled out automatically by the platform. No maintenance window, no environment left behind.

## You see what we see

Security you cannot verify is a promise, not a fact. So as an administrator you see for yourself what happens in your environment: the logs, the blocks and the way they are managed.

- Request logs with traffic insight per environment

- View and lift IP bans, manage the allowlist yourself

- Metrics endpoints for your own monitoring stack

![Statistics for a Core cluster: usage, performance and traffic per environment](https://rual.nl/site-assets/_opt/cluster_analytics-960.webp)

## Every request is seen

Active threat protection runs underneath every environment. All traffic is logged and monitored, and the cluster intervenes on its own when it spots an attack pattern. A ban on one node applies across the whole cluster immediately.

- Every API request logged: method, path, IP, user, status, timing and origin. Sensitive values are masked before storage.

- Automatic IP ban on brute force and attack patterns: injection, scanners and probes get 30 days on the spot.

- Cluster audit log: who viewed a secret, who created users, who lifted a ban. Kept for 7 years.

- Live metrics per environment (CPU, memory, requests, latency, errors) through secured Prometheus-compatible endpoints, for your own monitoring too.

**Cluster monitoring** — sample data

- `14:02:11` api.request · /orders · 200 · logged

- `14:02:09` audit · secure setting viewed by administrator

- `14:01:52` threat · scanner signature detected in request (held for review)

- `14:01:52` auto-ban · IP blocked for 30 days (completed)

### The foundation: Dutch data centres, European law

Everything above runs on our own hardware in ISO-certified data centres in Ede. Fully European, so no US CLOUD Act.

[About our hosting →](https://rual.nl/en/hosting)

## Want to know what this looks like for your environment?

We are happy to show it live, with your questions on the table. Found something yourself? See our [responsible disclosure](https://rual.nl/en/responsible-disclosure).

[Book a demo](https://rual.nl/en/demo)

[Get in touch](https://rual.nl/en/contact)
