Security at Rattib

Practical safeguards, built into the service.

Rattib combines clear account choices, controlled sharing, protected connections, scoped access, recoverable backups, and direct deletion controls.

Core protections

Security follows the data through its lifecycle.

Controls are applied from sign-in and upload through sharing, synchronization, backup, and deletion.

01

Protected connections

The website and Cloud service use HTTPS to protect information while it travels between your device and Rattib.

02

Scoped access

Inventory records and photos are checked against ownership and active sharing permissions before access is granted.

03

Session security

Access sessions are time-limited and can be revoked when an account is deleted or suspicious activity is detected.

04

Trusted sign-in

Cloud accounts use Sign in with Apple or Google. Password signup, login, and recovery are disabled.

05

Controlled sharing

Owners invite members by username or approve QR share requests. Access is limited to Owner or read-only Guest, and a space can have multiple Owners.

06

Deletion controls

Delete Account and All Data revokes active sessions, removes Cloud inventory and photos, disconnects sign-in providers, and de-identifies the remaining account record.

Cloud and continuity

One authority with a protected last-known view.

Cloud remains authoritative. A saved device copy improves startup and temporary read-only access without becoming a second inventory.

Cloud authority

Inventory changes require a live authenticated Cloud preflight and reconcile against the latest server state.

Encrypted saved metadata

A previously synchronized snapshot is bound to the signed-in session and environment, contains no photo bytes, and is cleared on sign-out.

Shared access

Owners invite usernames or approve QR share requests and assign Owner or strictly read-only Guest access.

Photos

Cloud photo requests require authorization. Originals and thumbnails follow the same ownership and sharing rules as the associated inventory.

Reliability and recovery

Designed to recover without weakening access controls.

Operational safeguards help protect service continuity while keeping recovery material isolated from the public application.

Encrypted backups

Cloud inventory and photo backups are encrypted and retained on a rotating daily, weekly, and monthly schedule.

Integrity checks

Stored files use integrity checks, and restore procedures verify inventory and photo consistency.

Safe recovery

Reads retry automatically. A mutation is never silently queued or automatically resubmitted after an uncertain result.

Responsible disclosure

Found something that could put people or data at risk?

Email a clear description to support@rattib.com with the subject “Security report.” Please avoid accessing data that is not yours, disrupting the service, or publicly disclosing an issue before we have had a reasonable opportunity to investigate.

Contact security