Teams page · The honest version

Built for practitioners. Ready for the questions teams ask.

R-MAP is practitioner-first by design: individual professionals adopt an instrument, prove it on real work, and the organization follows the evidence. This page answers — plainly — what a team evaluator will ask about security, data, continuity, and procurement, and describes the pilot path for departments that want to move earlier.

An enterprise command center running R-MAP instruments
One practitioner first · then the team
01 · What your security review will find

Small surface, honest architecture.

These are the answers to the standard vendor-review questions, stated the way your reviewer wants them stated.

Data architecture

Local-first by design

  • Model inputs stay on the device registers, scenarios, and scores live in the page and the browser's local storage — they reach R-MAP's servers only when a member explicitly saves a cloud scenario or requests a server-side score.
  • Portable, inspectable state every instrument exports its full state as plain JSON (⤓ Save to file) — no lock-in, nothing opaque.
  • Minimal account data email, a bcrypt password hash, membership status. The full inventory is on the Privacy page — it is short.
  • No trackers no analytics SDKs, no pixels, no ad tech. The only cookie-like object is your own session token.
Platform controls

The same rigor the models preach

  • Server-side gating protected content and scoring IP are enforced on the server; there is no public URL that bypasses membership.
  • Signed sessions HMAC-signed, time-limited tokens compared in constant time; HTTPS everywhere.
  • Least privilege the database user is scoped to exactly what the platform needs; billing (when live) is Stripe-only — card numbers never touch R-MAP.
  • Honest gaps no SSO/SAML yet, no SOC 2 report yet, no per-seat audit trail yet. These arrive with team licensing, not before — you should know that going in.
02 · Continuity

The one-maker question, answered directly.

R-MAP is built and run by one person. Your procurement team will raise it, so here is the mitigation, not a deflection.

Your work survives regardless

Every instrument runs as a self-contained page and exports portable JSON. If R-MAP vanished tomorrow, your saved files still open, your data is still yours, and nothing you built is stranded in a proprietary cloud.

Versioned and documented

The platform keeps a running changelog, and every model carries its method openly — formulas visible, sample data labeled, assumptions inspectable. Nothing depends on undocumented magic.

Backed up and boring

Server state is small (accounts and saved scenarios), encrypted in transit, backed up on AWS infrastructure. Boring is the point.

Escrow on request

Departmental agreements can include a source-continuity clause — code escrow or a wind-down license — negotiated per contract. Ask; it is not a strange request.

03 · The path for a team

Practitioner → pilot → department.

The sequence is deliberate. Tools that arrive attached to a practitioner who already trusts them clear procurement faster than any demo.

Step 1 · Today

One practitioner, real work

An individual membership. Run the instrument on live decisions — a board paper, a covenant review, an exposure assessment. Keep the outputs; they become the internal case study.

Step 2 · When it sticks

The 90-day pilot

A structured departmental pilot: 5–15 named seats, invoice/PO billing, agreed success criteria up front (decisions supported, hours saved, artifacts produced), and a mid-point check. Priced as a pilot, not a subscription.

Step 3 · If it earns it

Team licensing

Team access is on the roadmap and pilots shape it: shared scenarios, an admin view, and the SSO/audit controls a department needs. Pilot partners get grandfathered pricing and a louder voice in what ships first.

Interested in a pilot — or just want the security answers as a PDF for your reviewer? Email directly or use the request form and mention your team size; those requests are read first.