Skip to content
Replyion
Legal · Security

Security

Last updated: 2026-07-22

Encryption

All traffic is encrypted in transit with TLS 1.2 or higher (TLS 1.3 preferred). Data is encrypted at rest with AES-256, covering both the database and backups. Google OAuth tokens and human-takeover contact details carry an additional application-layer encryption using AES-256-GCM.

Tenant isolation

Every clinic’s data is isolated per clinic with PostgreSQL row-level security, enforced in the database itself rather than only in application code.

Audit logging

Security-relevant actions are written to an append-only audit log. Updates and deletes of audit records are blocked at the database level.

Access control

Access follows least privilege, and production access is logged. Development and production run in separate environments with separate databases.

Data residency and backups

Data is stored at rest in the EU (Frankfurt). Backups are encrypted and held off-platform.

Credentials

We operate a credential rotation policy for production secrets.

Breach notification

We commit to notifying affected clinics within 72 hours of confirming a personal data breach affecting their data.

Sub-processors

The maintained list of sub-processors, with locations and status, is at /legal/sub-processors.

Reporting concerns

Report security concerns to hello@replyion.com.