On this page
Encrypted
All data encrypted in transit and at rest
Protected
Industry-standard access controls
PCI Safe
Card data never stored on our servers
Overview
At OptiReply, we take the security of your business data seriously. We implement industry-standard practices to protect customer data, ensure platform reliability, and maintain your trust.
Data Protection
We protect all data passing through OptiReply with multiple layers of security:
- All data in transit is encrypted using HTTPS/TLS
- Database data is encrypted at rest
- Secure authentication with hashed password storage — plaintext passwords are never stored
- Role-based access controls limit data exposure within the platform
- Session tokens are securely managed and expire automatically
Infrastructure
Our platform is built on secure, enterprise-grade cloud infrastructure designed for reliability and security.
- Backend, database, and application hosting run on Google Cloud Platform, certified to SOC 2 and ISO 27001 standards
- Production availability and infrastructure health are monitored using configured Google Cloud uptime checks and alerting policies
- Regular automated backups with point-in-time recovery
Access Control
- Only authorized personnel can access sensitive systems
- Internal access follows least-privilege principles — staff access only what their role requires
- Application and infrastructure events are logged using platform and application logging controls
Payment Security
- All payments are processed exclusively through Stripe — a PCI DSS Level 1 certified provider
- Card details are tokenized by Stripe and never touch our systems
- Subscription management and billing history are handled securely through Stripe's infrastructure
Third-Party Security
All third-party providers used by OptiReply are evaluated for security standards before engagement and are required to maintain appropriate safeguards.
- Google Cloud Platform — ISO 27001, SOC 2, SOC 3, and more
- Stripe — PCI DSS Level 1 certified
Data Retention & Deletion
- Users can delete their account and data at any time
- Most customer operational data is deleted from active application systems when a verified account-deletion request is completed. Certain billing, audit, account, and legally required records may be retained for financial, security, or compliance purposes. See our Data Deletion Policy for details.
Incident Response
In the event of a security incident involving your data:
- We investigate immediately upon detection
- Affected users are notified within 72 hours if required by law or if data is at risk
- Corrective actions are implemented and documented
- A post-incident review is conducted to prevent recurrence
Vulnerability Disclosure
If you discover a security vulnerability in OptiReply, please report it responsibly. We ask that you:
- Email us at privacy@seven9it.com with details
- Give us reasonable time to investigate and remediate before public disclosure
- Avoid accessing, modifying, or deleting data that isn't yours
We will acknowledge all responsible disclosures and work with you to resolve confirmed issues.
Contact
Security questions or concerns? Reach out directly: