Trust & Safety

Security that doesn't sleep.

Your customer data is the most valuable thing you've got. We treat it that way — every layer, every day.

🔐

Encryption everywhere

AES‑256 at rest. TLS 1.3 in transit. Tenant API keys and access tokens encrypted with a per‑install key.

🔑

Strong authentication

Bcrypt-hashed passwords, session cookies hardened with HttpOnly + SameSite, and session regeneration on login.

🛡️

CSRF on every form

Every state-changing request requires a per-session CSRF token. Forged requests are rejected at the door.

📜

Audit log on everything

Every admin action, every login, every privileged change is logged with actor, timestamp and IP — exportable for your audits.

🧪

Prepared statements only

Every database query uses prepared statements. SQL injection is structurally impossible.

🚷

Tenant isolation

Every query is scoped by tenant. You can't accidentally — or intentionally — see another customer's data.

How we operate

Boring is good.

No move-fast-and-break-things. Defaults are safe, changes are reviewed, mistakes are documented.

Code review & deployment

Every change is reviewed before it ships. Production secrets live in encrypted environment variables, never in code. Deployments are logged and reversible.

Backups & recovery

Encrypted database backups every 6 hours, retained 30 days. Tested restore procedure documented. RPO 6 hours, RTO 4 hours.

Vendor security

Every sub-processor is vetted, contractually bound, and listed publicly in our Privacy Policy. We add new ones with 30 days' notice.

Vulnerability response

Found a security issue? Email security@whatareply.com. We acknowledge within 24 hours and will keep you updated until it's fixed. Responsible disclosure is welcomed and rewarded.

Compliance & certifications

The boring stuff. Done properly.

GDPR aligned
CCPA aligned
SOC 2 Type I (in progress)
ISO 27001 (planned)
Meta Business Partner
AES-256 at rest
TLS 1.3 in transit
EU / IN / US data residency

Need our security questionnaire (CAIQ, SIG Lite) or a SOC report once issued? Email security@whatareply.com.

Have a question your security team needs answered?

We respond to every security-related email within one business day — usually faster.