Implemented safeguards
The OpenAI API key is used server-side, input is validated before generation, and production-facing errors avoid exposing provider details or stack traces.
This page documents implemented safeguards and known product limits.
The OpenAI API key is used server-side, input is validated before generation, and production-facing errors avoid exposing provider details or stack traces.
ReplyWise stores authenticated account details, workspace records, settings, usage events, and audit records in Supabase. The app does not use a committed storage upload runtime or an external analytics platform.
The advisor prompt and internal product logic are designed to avoid aggressive, deceptive, manipulative, illegal, or unsafe business replies. They are not a guarantee of moderation, legal compliance, factual correctness, or suitability for a particular situation. Review and approve every draft before sending it.
To report a security concern, use the verified security contact. Do not include credentials, authentication links, or sensitive customer data.
Formal incident response and SOC2 controls are not represented as implemented in this repository.