how we protect you —

Security Practices

Security isn't a checkbox — it's a habit. Here's exactly what we do to keep your family's data safe.

Last updated: February 12, 2026

TLS 1.3 in transit
Active
AES-256 at rest
Active
SOC 2 Type II (in prog.)
In progress
MongoDB Atlas encrypted
Active
Role-based access
Active
24/7 monitoring
Active

Encryption

All data is encrypted in transit using TLS 1.3, and at rest using AES-256. Backups are encrypted with separate keys stored in a dedicated key-management service.

Access control

  • Employee access is role-based, minimum-privilege, and audited quarterly.
  • Production access requires SSO with hardware-key 2FA (WebAuthn / FIDO2).
  • No employee has direct read access to student session transcripts.

Infrastructure

  • Hosted on AWS / GCP data centers in ISO 27001-certified regions.
  • Isolated environments for dev, staging, and production.
  • Automatic patching, WAF, DDoS protection, and rate limiting at the edge.

Third-party risk

Every sub-processor (Deepgram, Sarvam, Anthropic, Google, OpenAI, MongoDB) is reviewed for SOC 2 / ISO compliance before we integrate. Contracts include data-protection addendums.

Incident response

We have a documented incident response plan. In the unlikely event of a breach affecting your data, we'll notify you within 72 hours and file with regulators as required.

Reporting a vulnerability

Email security@reppx.ai with details. Include steps to reproduce. We aim to acknowledge within 24 hours and fix critical issues within 7 days.

© 2026 Naught Logic Pvt Ltd. All rights reserved.
legal@reppx.aiHyderabad, India