Security
RepWorth protects review, billing, and approval data with scoped access, hashed approval tokens, and controls for authorized publishing.
Vulnerability disclosure
Report suspected vulnerabilities to security@repworth.net. We will acknowledge receipt, investigate in good faith, and avoid legal action for good-faith research that avoids data destruction, service disruption, and access to other customers' data.
Current status
- Approval tokens are stored as SHA-256 hashes, not raw tokens.
- Copilot replies require individual owner approval. Where available, Autopilot can publish eligible replies only under an expressly enabled policy and its limits, waiting period, and safety checks. A subscription alone does not authorize automatic posting.
- Tenant access is enforced in application code. Every owner read and write is scoped to your account and location. Row-level security policies are additionally enabled on protected database tables as a defense-in-depth backstop.
- Screening on connected-review ingestion is designed to block some likely protected health information (PHI). Detection is limited and may miss sensitive information. Do not submit private health records or assume that screening makes the Service HIPAA compliant.
- We do not claim SOC 2 certification or provide a SOC 2 report on this page.
- Authorized personnel may access information for support, security, and service operation. No security control guarantees that every incident will be prevented.
Legal and privacy
See Privacy, Terms, and Sub-processors.