Skip to content
Launch special: 50% off your first 2 months· 50% off for 2 months

Security

Your customers trust you. You should be able to trust us.

Here's how RepeatCrew actually protects your data: what's enforced, where, and what we don't claim. No vague badges.

Isolated by design

Row-level security on every table keeps each business's data separate at the database layer.

Least-privilege roles

Five roles, enforced in the database, not just hidden in the interface.

No card numbers, ever

Payments run through Stripe. RepeatCrew never sees or stores card details.

Accountable AI

Every AI action is logged, and guardrails run before anything is sent.

Tenant isolation

Enforced by the database, not by hope.

Row-level security on every table

Every business record carries its organization ID, and Postgres row-level security is enabled on every table in the application schema. Queries only ever return rows for workspaces you're a member of, even if application code has a bug.

Composite tenant foreign keys

Related records reference each other by organization and ID together. A lead, invoice, or appointment physically cannot point at another business's customer, even from privileged server code.

No anonymous database access

The public database role has no table privileges at all. Public pages like online booking, hosted lead forms, and estimate or invoice links are served by our servers, which only return what that page needs.

Access control

The right access for every teammate.

Permissions are checked in the app and enforced again by database policies, so hiding a button is never the only protection.

  • ViewerRead-only access to the workspace.
  • StaffWork leads, customers, conversations, appointments, estimates and invoices; record non-card payments; review AI actions.
  • ManagerEverything staff can do, plus services, automations, AI team settings, and deleting records.
  • AdminEverything managers can do, plus organization settings, members, billing, and integrations.
  • OwnerFull control, including granting and revoking ownership. Every workspace always keeps at least one owner.

Secrets, transport & payments

Sensitive things stay where they belong.

Privileged keys never reach the browser

The database service-role key and provider API keys live only on the server. Code that uses elevated access filters every query by organization explicitly.

Encrypted in transit and at rest

All traffic to RepeatCrew and between RepeatCrew and its providers is sent over HTTPS/TLS, and stored data is encrypted at rest. Integration credentials you connect are encrypted before they're stored.

Stripe handles card data

Deposits, invoices, and subscriptions are paid through Stripe. Card numbers go directly to Stripe; RepeatCrew never receives or stores them.

AI safety

An AI team with rules it can't talk its way around.

Every action logged

AI actions are recorded with what was proposed, why, and what happened. In approve mode, nothing is sent until someone on your team signs off.

Quiet hours and message caps

Autonomous replies pause during your quiet hours and stop after a set number of unanswered messages, so no one gets spammed.

Consent and opt-outs enforced

Messages only go to contacts who can receive them on that channel. Opt-outs and do-not-contact flags are checked before every send.

Human handoff

Complaints, refunds, and urgent or sensitive issues are flagged for a person instead of being answered automatically. The AI never claims to be human.

Audit log

A record that can't be rewritten.

Meaningful changes by people, automations, and AI agents are written to an append-only activity log. Update and delete permissions are revoked at the database level, so entries can be added but never edited or removed from the app.

What we don't claim

RepeatCrew does not currently hold third-party certifications such as SOC 2, ISO 27001, or HIPAA attestation, and it isn't designed for protected health information or other regulated data. If your business has specific compliance requirements, please talk to us before signing up.

Found a vulnerability? Please report it through our contact page and we'll respond promptly.

Stop losing leads to slow replies.

Start your 14-day free trial with everything in Growth. No credit card, no contracts, cancel anytime.

  • 14-day free trial
  • No credit card required
  • Cancel anytime