Encryption
All data is encrypted in transit using TLS 1.3, and at rest using AES-256. Backups are encrypted with separate keys stored in a dedicated key-management service.
Access control
- Employee access is role-based, minimum-privilege, and audited quarterly.
- Production access requires SSO with hardware-key 2FA (WebAuthn / FIDO2).
- No employee has direct read access to student session transcripts.
Infrastructure
- Hosted on AWS / GCP data centers in ISO 27001-certified regions.
- Isolated environments for dev, staging, and production.
- Automatic patching, WAF, DDoS protection, and rate limiting at the edge.
Third-party risk
Every sub-processor (Deepgram, Sarvam, Anthropic, Google, OpenAI, MongoDB) is reviewed for SOC 2 / ISO compliance before we integrate. Contracts include data-protection addendums.
Incident response
We have a documented incident response plan. In the unlikely event of a breach affecting your data, we'll notify you within 72 hours and file with regulators as required.
Reporting a vulnerability
Email security@reppx.ai with details. Include steps to reproduce. We aim to acknowledge within 24 hours and fix critical issues within 7 days.