Security

How we protect your data.

Reviewcast reads public store listings — it needs no SDK in your app and no access to your users’ data.

Encryption

All traffic uses TLS 1.2+. Data is encrypted at rest, including backups, and store credentials with AES-256.

Access control

Least-privilege staff access, enforced 2FA, audit logs on administrative actions, and per-tenant isolation at the database layer.

Credentials you give us

Store credentials for posting replies are encrypted, never displayed again, and used only for actions you trigger.

Webhook integrity

Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify every payload came from us.

Backups & recovery

Automated daily backups with periodic restore testing. Review history can be re-ingested from the stores if ever needed.

Minimal surface

Monitoring needs no connection to App Store Connect or the Play Console. Credentials are optional and only for replies.

Found a vulnerability?

Email security@reviewcast.co. We acknowledge within 48 hours and won’t act against good-faith research.

Read the DPA