Security

Security

This page documents implemented safeguards and known product limits.

Implemented safeguards

The OpenAI API key is used server-side, input is validated before generation, and production-facing errors avoid exposing provider details or stack traces.

Data storage

ReplyWise stores authenticated account details, workspace records, settings, usage events, and audit records in Supabase. The app does not use a committed storage upload runtime or an external analytics platform.

AI safety

The advisor prompt and internal product logic are designed to avoid aggressive, deceptive, manipulative, illegal, or unsafe business replies. They are not a guarantee of moderation, legal compliance, factual correctness, or suitability for a particular situation. Review and approve every draft before sending it.

Security contact

To report a security concern, use the verified security contact. Do not include credentials, authentication links, or sensitive customer data.

Operational boundaries

Formal incident response and SOC2 controls are not represented as implemented in this repository.