Compliance
- GDPR-native by design, built in Spain by EterSystem. Spanish supervisory authority (AEPD).
- Certifications: Repify does not currently hold SOC 2, ISO 27001 or other third-party security certifications.
- Google Business Profile API: official API, accessed only via Google OAuth2.
Infrastructure
Production runs on our hosting provider's managed infrastructure. We don't offer an uptime SLA.
Backups encrypted, retention rolling 30 days.
Encryption
- In transit: TLS 1.3 everywhere, HSTS preload, strong cipher suites only.
- At rest: AES-256 encryption on all databases and backups.
- Passwords: bcrypt with cost factor 12, never stored in plaintext.
Access controls
- Customer accounts: bcrypt passwords; team members join only by email invitation to a workspace.
- Repify employees: mandatory 2FA, role-based access, all production access logged.
- Google data: we connect via OAuth2, scoped to the minimum (read reviews, post replies). You can revoke from your Google account or from Repify with one click.
- Reply history: every published reply records when it was sent and whether it was sent manually or by an auto-reply rule.
AI and your data
Drafts are generated via OpenAI models. OpenAI contractually does not train on API-submitted data. Repify does not train on customer data either. Transfers outside the EU are covered by Standard Contractual Clauses (SCCs).
Operational security
- Production deploys require two-person approval.
- Dependencies scanned daily for known vulnerabilities.
- Penetration test annually by an independent firm. Findings remediated within 30 days.
- Internal incident response plan tested quarterly.
- Status page at status.repify.tech with real-time uptime.
Responsible disclosure
If you find a security issue, email security@repify.tech. We aim to acknowledge within 24 hours and resolve within 30 days. We don't run a paid bug bounty yet, but we publicly credit responsible disclosures (with your permission) and send swag.
Please don't run automated scanners against production without coordinating — we'd rather work with you than block your IP.
Past incidents
We publish post-mortems for any incident affecting customer data or causing more than 30 minutes of downtime. Browse them at status.repify.tech. Most recent material incident: never (zero data-affecting incidents since founding).