All traffic is encrypted in transit with TLS 1.2+. Data is encrypted at rest, including backups.
Least-privilege access for staff, enforced 2FA, and audit logs on administrative actions. Production access is limited to on-call engineers.
Store credentials for posting replies (API keys, service accounts) are stored encrypted and used only for the actions you trigger.
Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify every payload came from us.
Automated daily backups with periodic restore testing. Review history can be re-ingested from the stores if ever needed.
Reviewcast reads public store listings — it needs no SDK in your app and no access to your codebase or user data.
Report it to security@reviewcast.co. We acknowledge reports within 48 hours and won’t take action against good-faith research.