Every part of Rallly is built to protect your data, on trusted infrastructure with a codebase anyone can audit. Your schedule is nobody's business but yours.
people voted on polls in the last 30 days
How we run the service, where your data lives, and what we commit to. Where most vendors ask you to take their word for it, we publish the evidence.
The full source code is public and auditable on GitHub. Anyone can review exactly how data is handled.
Browse source codeMeasured uptime above 99.9%, published in real time on an independent status page. Not self-reported.
View live statusPrefer full control? Run Rallly on your own infrastructure and your data never reaches us.
Learn moreTLS 1.2 or higher for all traffic, AES-256 encryption at rest, and HTTPS enforced across the platform.
We collect the minimum needed to run the service. No sensitive personal information, no advertising trackers, and we never sell data.
Data is scoped to its owner at the access layer, with the architecture rules enforced by static analysis in the codebase.
Rallly runs on the world's leading infrastructure providers, giving you the security and performance you should expect. Here is the complete list, and where your data lives.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | United States |
| DigitalOcean | Managed PostgreSQL database | United States |
| Upstash | Session data, rate limiting | United States |
| Amazon Web Services | Transactional email, object storage | United States |
| Stripe | Payment processing (billing contact data only) | United States |
| PostHog (EU) | Product analytics | European Union |
| Sentry | Error monitoring | United States |
The answers we give when organizations evaluate Rallly. If your review needs something not covered here, we are happy to complete your security questionnaire.
Very little by design. Account holders provide a name, email address, and timezone preference. Poll participants provide a name and optionally an email address, and vote as guests without needing accounts. We collect no sensitive personal information, no government identifiers, and no financial account details.
Data is retained while your account is active. You can delete polls and your account at any time, and account deletion takes effect immediately. Inactive polls are automatically scheduled for deletion with a 30 day grace period and advance notice. On request, we delete an organization's data and confirm deletion in writing, and your data is exportable in standard formats at any time.
Not currently. Our infrastructure providers are SOC 2 Type 2 and/or ISO 27001 certified, and their attestations are available from each provider. In place of certification we offer what most certified vendors cannot: fully auditable source code, public real-time uptime monitoring, and direct access to the people who build the product.
Sign in works with email verification codes, Google, or Microsoft accounts. All inputs are schema-validated, database access goes through a typed ORM with parameterized queries, and dependencies are monitored for vulnerabilities with automated security updates. Every production change goes through version control, code review, automated tests, and staged deployment with instant rollback.
Monitoring and alerting route directly to the engineering team. If a security incident affects your data, we will notify you within 72 hours of becoming aware of it. Rallly has had no data breaches.
Members can sign in with their Google or Microsoft accounts today. Organization-wide SSO enforcement is on our roadmap as part of upcoming organization features.
The production database is backed up automatically every day with point-in-time recovery, managed by our database provider. The application runs on globally distributed serverless infrastructure and can be redeployed rapidly.
Yes. We complete security and privacy questionnaires for organizational customers, and most answers map directly to the information on this page. Send it to support@rallly.co.
We are happy to answer questions, complete your security review, or talk through deployment options, including self-hosting on your own infrastructure.