Security

How we protect your data.

Security practices at Reviewcast, in plain language. For contractual terms, see the DPA.

Encryption

All traffic is encrypted in transit with TLS 1.2+. Data is encrypted at rest, including backups.

Access control

Least-privilege access for staff, enforced 2FA, and audit logs on administrative actions. Production access is limited to on-call engineers.

Credentials you give us

Store credentials for posting replies (API keys, service accounts) are stored encrypted and used only for the actions you trigger.

Webhook integrity

Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify every payload came from us.

Backups & recovery

Automated daily backups with periodic restore testing. Review history can be re-ingested from the stores if ever needed.

Minimal surface

Reviewcast reads public store listings — it needs no SDK in your app and no access to your codebase or user data.

Found a vulnerability?

Report it to security@reviewcast.co. We acknowledge reports within 48 hours and won’t take action against good-faith research.

Read the DPA →