Security · Updated May 13, 2026

How we keep your data safe.

GDPR-native, built in Spain by EterSystem, OAuth2-only Google access, encrypted in transit. The short version is below.

Compliance

  • GDPR-native by design, built in Spain by EterSystem. Spanish supervisory authority (AEPD).
  • Certifications: Repify does not currently hold SOC 2, ISO 27001 or other third-party security certifications.
  • Google Business Profile API: official API, accessed only via Google OAuth2.

Infrastructure

Production runs on our hosting provider's managed infrastructure. We don't offer an uptime SLA.

Backups encrypted, retention rolling 30 days.

Encryption

  • In transit: TLS 1.3 everywhere, HSTS preload, strong cipher suites only.
  • At rest: AES-256 encryption on all databases and backups.
  • Passwords: bcrypt with cost factor 12, never stored in plaintext.

Access controls

  • Customer accounts: bcrypt passwords; team members join only by email invitation to a workspace.
  • Repify employees: mandatory 2FA, role-based access, all production access logged.
  • Google data: we connect via OAuth2, scoped to the minimum (read reviews, post replies). You can revoke from your Google account or from Repify with one click.
  • Reply history: every published reply records when it was sent and whether it was sent manually or by an auto-reply rule.

AI and your data

Drafts are generated via OpenAI models. OpenAI contractually does not train on API-submitted data. Repify does not train on customer data either. Transfers outside the EU are covered by Standard Contractual Clauses (SCCs).

Operational security

  • Production deploys require two-person approval.
  • Dependencies scanned daily for known vulnerabilities.
  • Penetration test annually by an independent firm. Findings remediated within 30 days.
  • Internal incident response plan tested quarterly.
  • Status page at status.repify.tech with real-time uptime.

Responsible disclosure

If you find a security issue, email security@repify.tech. We aim to acknowledge within 24 hours and resolve within 30 days. We don't run a paid bug bounty yet, but we publicly credit responsible disclosures (with your permission) and send swag.

Please don't run automated scanners against production without coordinating — we'd rather work with you than block your IP.

Past incidents

We publish post-mortems for any incident affecting customer data or causing more than 30 minutes of downtime. Browse them at status.repify.tech. Most recent material incident: never (zero data-affecting incidents since founding).

Have a security question?

Email security@repify.tech.

Security questionnaires and disclosure reports are answered by the team that builds the product.