Security Posture
Three pillars of data protection
Encryption in transit and at rest
All data moving between Replylume and your integrated platforms travels over TLS 1.3. Data stored at rest, including ticket context, audit logs, and access tokens, is encrypted with AES-256. Credentials are never stored in plaintext.
- TLS 1.3 for all API communication
- AES-256 encryption for stored data
- OAuth tokens stored with envelope encryption
Minimal API scope by default
Replylume requests the narrowest possible OAuth scope for each integration. Billing APIs are read-only by default. Refund write access is a separate, explicit permission that you grant only when enabling refund automation. CRM scope is limited to activity log fields only.
- Billing API: read-only unless refund scope explicitly granted
- CRM API: activity/engagement write only, no contact modification
- Help desk API: ticket read + status write (resolve action only)
Immutable audit log on every action
Every automated action taken by Replylume is logged: timestamp, action type, ticket reference, data sources queried, decision outcome, and execution result. The log is append-only. No action can be taken without a corresponding log entry being created first.
- Append-only log format, no post-hoc edits
- Each entry includes decision trace (why the action was taken)
- Log export available on Growth and Scale plans
Compliance Approach
Designed with data minimization in mind
We do not hold certifications we haven't earned. Here is what we have done, and how it maps to GDPR and CCPA principles.
No training on your data
Replylume does not use ticket content, customer data, or CRM records to train any model. The data accessed during a resolution session is used only to execute that session and write the audit log entry. It is not retained beyond the plan's stated retention window, and never used as training input.
GDPR data minimization design
Replylume's data access pattern is designed with GDPR Article 5(1)(c) data minimization in mind: we access only the fields required to execute the specific action (order ID, amount, refund eligibility, CRM contact reference). We do not read full PII profiles, purchase history, or fields unrelated to the current ticket.
CCPA cross-reference handling
For customers in California, Replylume does not sell or share personal information as defined under CCPA. Ticket data accessed during a session is treated as service data only. You remain the controller; Replylume acts as a processor under your direction and within your configured scope limits.
What we have not yet certified
Replylume launched in 2025 and is working toward SOC 2 Type II. We will not claim a certification we do not hold. If your procurement process requires SOC 2 or ISO 27001 today, email us at [email protected] and we will share the current controls documentation and expected certification timeline.
Audit Trail
Every action is attributable
No action by Replylume is invisible. Here is what a typical audit log entry looks like.
rpl_exec_4882a71c
2026-06-11T23:47:10Z
refund_issuance
ZD-48821
stripe:charges (read), hubspot:engagements (write)
rule:refund_eligible, confidence:0.94
stripe:refund:ch_3Qx7rMnP ($89.00) + zendesk:ticket:close + hubspot:engagement:create