Security
Last updated January 1, 1970.
A plain description of what is actually in place. We do not claim certifications we have not completed.
Data protection
- All traffic between your device and the service is encrypted with TLS.
- Data at rest is encrypted by our managed database and storage providers.
- Passwords are hashed by our authentication provider; we never see them.
- Secrets and API keys are stored server-side and are never exposed to the browser.
Access control
- Every record is scoped to a single business and checked on the server for each request.
- Team members have roles that limit what they can see and change.
- Administrative capability is granted separately and is not stored on user profiles, so it cannot be self-assigned.
- Sensitive actions are recorded in an audit log.
Application security practices
- Input is validated on the server as well as in the browser.
- Public pages expose only the minimum data needed and are not indexed.
- Automated security checks run against the database and application configuration.
- Dependencies are monitored and updated for known vulnerabilities.
Hosting and availability
The application and database run on managed cloud infrastructure, and database backups are handled by that provider under its own schedule. Application errors are captured and reviewed so problems that affect customers can be investigated.
Your data stays yours
- Your customer records and conversations belong to your business, not to us.
- We do not sell customer lists and do not share your customer data with other businesses.
- Automated replies are generated from the business information you configure.
- A person on your team can take over any conversation at any time.
- Customers can reply STOP to opt out, and opted-out numbers are blocked on every send path.
- You can delete your business and its data from Settings → Account.
Incident response
If a breach affects your data we will investigate, contain it, and notify affected account owners without undue delay along with what happened and what to do.
Compliance status
We are not currently certified under SOC 2, ISO 27001 or HIPAA and do not claim to be. Do not send protected health information or payment card numbers through conversations.
Reporting a vulnerability
Report suspected vulnerabilities privately and give us reasonable time to fix them. We will not pursue action against good-faith research that avoids privacy violations and service disruption.
Security contact: support@justrply.com