Security
Platform security overview · Last updated: 25 May 2026
1. Overview
Reputify is operated by Joyful Designs as a multi-tenant SaaS platform. We use industry-standard practices to protect account data in transit and at rest. This page is a high-level summary—not a SOC 2 report.
2. Infrastructure
- HTTPS — production traffic is served over TLS
- Hosting — application and database on secured VPS/cloud infrastructure (India-first deployment)
- Secrets — API keys and OAuth tokens stored as environment secrets; Google refresh tokens encrypted at rest
- File storage — uploads and assets on local disk or S3 (per environment configuration)
3. Application security
- Session-based authentication with configurable session protection
- Role-based workspace access (owner, manager, viewer on supported plans)
- CSRF protection on state-changing forms
- Rate limiting on login, registration, webhooks, and public forms
- Security headers (HSTS, frame denial, CSP report-only) on public pages
- Webhook signature verification (e.g. Razorpay, WhatsApp) before processing
4. Account-holder controls (in-app)
Logged-in customers can use Security & Compliance settings:
- Privacy & Data Management — export or delete account data
- Session Management — view and revoke active sessions
- Password Policy — strength requirements and change flow
- Data Encryption & Security — overview of encryption practices
- Audit Logs — workspace activity history (Growth tier and above)
5. Incident response
We monitor production availability and investigate reported issues. If we confirm a breach affecting personal data, we will notify affected customers and processors as required by applicable law and our agreements. Report security concerns to contact@thejoyfuldesigns.com.
6. Related documents
Enterprise customers may request additional security questionnaires or a DPA review—contact sales or support.