Security
Your customers trust you. You should be able to trust us.
Here's how RepeatCrew actually protects your data: what's enforced, where, and what we don't claim. No vague badges.
Isolated by design
Row-level security on every table keeps each business's data separate at the database layer.
Least-privilege roles
Five roles, enforced in the database, not just hidden in the interface.
No card numbers, ever
Payments run through Stripe. RepeatCrew never sees or stores card details.
Accountable AI
Every AI action is logged, and guardrails run before anything is sent.
Tenant isolation
Enforced by the database, not by hope.
Row-level security on every table
Every business record carries its organization ID, and Postgres row-level security is enabled on every table in the application schema. Queries only ever return rows for workspaces you're a member of, even if application code has a bug.
Composite tenant foreign keys
Related records reference each other by organization and ID together. A lead, invoice, or appointment physically cannot point at another business's customer, even from privileged server code.
No anonymous database access
The public database role has no table privileges at all. Public pages like online booking, hosted lead forms, and estimate or invoice links are served by our servers, which only return what that page needs.
Access control
The right access for every teammate.
Permissions are checked in the app and enforced again by database policies, so hiding a button is never the only protection.
- ViewerRead-only access to the workspace.
- StaffWork leads, customers, conversations, appointments, estimates and invoices; record non-card payments; review AI actions.
- ManagerEverything staff can do, plus services, automations, AI team settings, and deleting records.
- AdminEverything managers can do, plus organization settings, members, billing, and integrations.
- OwnerFull control, including granting and revoking ownership. Every workspace always keeps at least one owner.
Secrets, transport & payments
Sensitive things stay where they belong.
Privileged keys never reach the browser
The database service-role key and provider API keys live only on the server. Code that uses elevated access filters every query by organization explicitly.
Encrypted in transit and at rest
All traffic to RepeatCrew and between RepeatCrew and its providers is sent over HTTPS/TLS, and stored data is encrypted at rest. Integration credentials you connect are encrypted before they're stored.
Stripe handles card data
Deposits, invoices, and subscriptions are paid through Stripe. Card numbers go directly to Stripe; RepeatCrew never receives or stores them.
AI safety
An AI team with rules it can't talk its way around.
Every action logged
AI actions are recorded with what was proposed, why, and what happened. In approve mode, nothing is sent until someone on your team signs off.
Quiet hours and message caps
Autonomous replies pause during your quiet hours and stop after a set number of unanswered messages, so no one gets spammed.
Consent and opt-outs enforced
Messages only go to contacts who can receive them on that channel. Opt-outs and do-not-contact flags are checked before every send.
Human handoff
Complaints, refunds, and urgent or sensitive issues are flagged for a person instead of being answered automatically. The AI never claims to be human.
Audit log
A record that can't be rewritten.
Meaningful changes by people, automations, and AI agents are written to an append-only activity log. Update and delete permissions are revoked at the database level, so entries can be added but never edited or removed from the app.
What we don't claim
RepeatCrew does not currently hold third-party certifications such as SOC 2, ISO 27001, or HIPAA attestation, and it isn't designed for protected health information or other regulated data. If your business has specific compliance requirements, please talk to us before signing up.
Found a vulnerability? Please report it through our contact page and we'll respond promptly.
Stop losing leads to slow replies.
Start your 14-day free trial with everything in Growth. No credit card, no contracts, cancel anytime.
- 14-day free trial
- No credit card required
- Cancel anytime
