Read-only by design
The ConnectWise connector is read-only by design. There is no write path: no rule edits, no disabling, no deletion, and no automatic remediation.
Security
RuleCerta will touch service-management configuration. The points below separate controls that exist today from design requirements that must be true before production. We do not claim certifications we do not hold.
The ConnectWise connector is read-only by design. There is no write path: no rule edits, no disabling, no deletion, and no automatic remediation.
Connections request only the configuration required for the audit and expect least-privilege read credentials. Live verification against an official ConnectWise production account remains pending external access; the product does not invent a live connection status.
Connector credentials are encrypted server-side. Secrets are never returned to the browser, never written to application logs, never sent to AI providers, and never attached to support tickets.
Access control does not rely on hidden buttons. Row-level security policies in PostgreSQL plus server-side authorisation restrict workspace and environment data to members. Direct browser table writes are denied.
A separate security event log covering sign-ins, credential changes, role changes and environment connections, with automatic secret redaction, is a design requirement before production. It is not in place today. Application error logging is not that control.
Production backup schedules and tested restore procedures are required before customer production and are not claimed as complete today. We do not treat the current database region as a public data-residency certification.
Customer data is not used to train models. An audit assistant is not offered today. If one is added later, it must only see data the signed-in user can already access, and it must never produce findings.
Workspace archive and restore, membership and invitations, and disconnecting a connector with credential wipe exist today. Exporting full workspace data and complete account-deletion workflows are still required before broad production customer data handling.
We do not claim SOC 2, ISO 27001 or HIPAA compliance, and we will not claim them until they are real. If a compliance requirement matters for your evaluation, contact us and we will answer precisely.