Security

Built to touch billing data responsibly

Replylume acts on billing and CRM data. That access requires a clear security posture. Every action is scoped, logged, and auditable before your security team asks.

Security Posture

Three pillars of data protection

Encryption in transit and at rest

All data moving between Replylume and your integrated platforms travels over TLS 1.3. Data stored at rest, including ticket context, audit logs, and access tokens, is encrypted with AES-256. Credentials are never stored in plaintext.

  • TLS 1.3 for all API communication
  • AES-256 encryption for stored data
  • OAuth tokens stored with envelope encryption

Minimal API scope by default

Replylume requests the narrowest possible OAuth scope for each integration. Billing APIs are read-only by default. Refund write access is a separate, explicit permission that you grant only when enabling refund automation. CRM scope is limited to activity log fields only.

  • Billing API: read-only unless refund scope explicitly granted
  • CRM API: activity/engagement write only, no contact modification
  • Help desk API: ticket read + status write (resolve action only)

Immutable audit log on every action

Every automated action taken by Replylume is logged: timestamp, action type, ticket reference, data sources queried, decision outcome, and execution result. The log is append-only. No action can be taken without a corresponding log entry being created first.

  • Append-only log format, no post-hoc edits
  • Each entry includes decision trace (why the action was taken)
  • Log export available on Growth and Scale plans

Compliance Approach

Designed with data minimization in mind

We do not hold certifications we haven't earned. Here is what we have done, and how it maps to GDPR and CCPA principles.

No training on your data

Replylume does not use ticket content, customer data, or CRM records to train any model. The data accessed during a resolution session is used only to execute that session and write the audit log entry. It is not retained beyond the plan's stated retention window, and never used as training input.

GDPR data minimization design

Replylume's data access pattern is designed with GDPR Article 5(1)(c) data minimization in mind: we access only the fields required to execute the specific action (order ID, amount, refund eligibility, CRM contact reference). We do not read full PII profiles, purchase history, or fields unrelated to the current ticket.

CCPA cross-reference handling

For customers in California, Replylume does not sell or share personal information as defined under CCPA. Ticket data accessed during a session is treated as service data only. You remain the controller; Replylume acts as a processor under your direction and within your configured scope limits.

What we have not yet certified

Replylume launched in 2025 and is working toward SOC 2 Type II. We will not claim a certification we do not hold. If your procurement process requires SOC 2 or ISO 27001 today, email us at [email protected] and we will share the current controls documentation and expected certification timeline.

Audit Trail

Every action is attributable

No action by Replylume is invisible. Here is what a typical audit log entry looks like.

AUDIT LOG ENTRY SUCCESS
Execution ID

rpl_exec_4882a71c

Timestamp

2026-06-11T23:47:10Z

Action Type

refund_issuance

Ticket Reference

ZD-48821

Data Sources Queried

stripe:charges (read), hubspot:engagements (write)

Decision Basis

rule:refund_eligible, confidence:0.94

Actions Taken

stripe:refund:ch_3Qx7rMnP ($89.00) + zendesk:ticket:close + hubspot:engagement:create