Reviewcast reads public store listings — it needs no SDK in your app and no access to your users’ data.
All traffic uses TLS 1.2+. Data is encrypted at rest, including backups, and store credentials with AES-256.
Least-privilege staff access, enforced 2FA, audit logs on administrative actions, and per-tenant isolation at the database layer.
Store credentials for posting replies are encrypted, never displayed again, and used only for actions you trigger.
Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify every payload came from us.
Automated daily backups with periodic restore testing. Review history can be re-ingested from the stores if ever needed.
Monitoring needs no connection to App Store Connect or the Play Console. Credentials are optional and only for replies.
Email security@reviewcast.co. We acknowledge within 48 hours and won’t act against good-faith research.