v2.0

GoRules Version 2 is here - redesigned, now with managed cloud.GoRules Version 2 is here!

Watch the launch videoWatch

Your infrastructure.
Your security.

GoRules is built for organizations with strict security and compliance requirements. Self-hosted deployment means your data never leaves your infrastructure.

SOC 2 Type IISelf-hostedSSO / OIDCRBACAudit logs

Your data never
leaves your environment.

Deploy GoRules on your own servers, VPC, or Kubernetes cluster. You keep full control over where and how your rules are stored and executed - under your existing security controls and compliance frameworks.

  • Self-hosted on your own infrastructure
  • AES-256 encryption at rest
  • TLS 1.3 between all components
  • Docker and Kubernetes deployments
View deployment options

Who can change what,
down to the action.

Access control that matches how rule changes actually happen - the right people author, the right people approve, and identity stays with your provider.

Role-based access control.

Fine-grained permissions control who can view, edit, approve, and publish rules. Create custom roles that match your organization structure.

Single sign-on via OIDC.

Integrate with your existing identity provider. Support for Okta, Azure AD, and other OIDC-compliant providers - no separate passwords to manage.

Every action, on the record.

A complete audit trail of every action - who changed what, when, and why. Approval workflows require reviews before rules go live, with multi-stage flows validating changes with the right people before deployment.

  • Multi-stage approval flows
  • Every sign-off recorded
  • Export logs to your SIEM

Security built in,
not bolted on.

Every layer of GoRules is designed so that a rule can never do more than decide - and so that nobody outside your organization ever sees your data.

Sandboxed execution

Rules execute in isolated environments with no access to filesystem or network.

Encryption everywhere

AES-256 encryption at rest, TLS 1.3 for communication between all components.

No data collection

We never see your business data. Everything stays in your infrastructure.

Regular audits

Third-party security assessments and penetration testing.

Compliance you
can verify.

Verified security controls, documented on our trust portal - not promised in a sales deck.

SOC 2 Type II

GoRules has obtained a SOC 2 Type II report, demonstrating our commitment to the highest security standards. View our trust portal for detailed compliance information.

View trust portal

Self-hosted deployments: when you deploy GoRules on your own infrastructure, you bring your own security controls - your compliance posture is determined by your cloud environment and internal policies.

Questions about
security?

Our team is happy to walk through your specific requirements - architecture, deployment, and compliance.