Security & Compliance

Your customers' conversations, treated with care.

Built so that your data is yours, stays in South Africa, is encrypted everywhere it moves and rests, and can be audited when your security team asks.

Encryption

Your data is encrypted at rest and in transit. Encryption keys are managed and rotated for you; nothing is stored or sent in the clear.

Your data stays yours

Every record is tied to your account at the database level, so your conversations, contacts and billing are visible only to the people you invite.

Sign-in and access

Password rules, two-factor authentication, roles for agents and supervisors, and audit logs of who did what. API keys are scoped to what an integration needs and can be rotated at any time.

Signed webhooks

Every event we send to your systems is signed, so your software can verify it came from us. Failed deliveries are retried and can be replayed from the console.

Money you can check

Every charge is explained on your usage page and every statement adds up. The books are checked automatically every night, so a discrepancy is found in hours, not at month end.

Hosted in South Africa

Your data is processed and stored in South Africa. It does not leave the country for routine operation.

POPIA posture

Designed around POPIA's principles: lawful purpose, minimisation, a record of every opt-in and opt-out, breach reporting, accuracy and accountability. Our POPIA page describes the stance in plain language.

Backups and recovery

Encrypted backups are taken regularly and restores are rehearsed, so a bad day for us is not a bad day for you.

Certifications & posture

Where we are, and where we are headed.

POPIA
By design
Data Processing Agreement
On request
Security overview
On request

Need to share this with your security team?

The DPA and the security overview are one form away. We reply the same business day.

Security & Compliance · RepletoryReach