1. Our Commitment
Security and privacy are foundational to Repaxio. We design our platform to protect the data of our Business Users and their customers using industry-standard safeguards and a defense-in-depth approach. This page summarizes our security practices; for how we handle personal data, see our Privacy Policy.
2. Infrastructure
Repaxio runs on Microsoft Azure cloud infrastructure located in the United States, benefiting from Azure's physical security, network controls, and platform certifications. We use a multi-tenant architecture with logical separation so each Business User's data is isolated from others.
3. Encryption
- Data encrypted in transit using TLS 1.2 or higher.
- Data encrypted at rest using AES-256.
- Secrets and API keys stored using managed secrets management.
4. Access Controls
- Authentication via Auth0 with support for multi-factor authentication (MFA).
- Role-based access controls (RBAC) for accounts and team members.
- Least-privilege access for internal administrative actions, with access logging and monitoring.
5. Monitoring, Backups, and Resilience
- Automated backups with disaster-recovery procedures.
- Logging and monitoring of administrative and security-relevant events.
- Regular security reviews and vulnerability assessments.
We target 99.9% platform availability, excluding scheduled maintenance. Specific service-level commitments may be set out in a customer agreement.
6. Sub-processors and Data Processing
We engage vetted sub-processors to deliver the Services. A current list is available on our Sub-processors page. Business Users who act as data controllers can request our Data Processing Addendum (DPA), which covers sub-processor disclosures, international transfer mechanisms, security measures, breach notification, and deletion obligations.
7. Breach Notification
We maintain an incident-response process. In the event of a personal data breach, we will notify affected customers and applicable authorities without undue delay and in accordance with applicable law (including, where applicable, notification to the Data Protection Board of India within 72 hours under the DPDP Act and notification obligations under GDPR and US state laws).
8. Compliance
We align our controls with recognized security frameworks (including the SOC 2 Trust Services Criteria) and continually invest in our compliance posture. To request current compliance documentation or to discuss your requirements, contact security@repaxio.com.
9. Responsible Disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in Repaxio, please report it privately to security@repaxio.com (see also our security.txt). We ask that you:
- Give us a reasonable opportunity to investigate and remediate before any public disclosure.
- Avoid privacy violations, data destruction, and service disruption while testing.
- Only test against your own account/data and not access other users' data.
We will acknowledge your report, keep you updated, and will not pursue legal action against researchers who act in good faith and within this policy.
10. Contact
Security questions or reports: security@repaxio.com.
© 2026 FoundHex Inc. All rights reserved.