1. Secure hosted proposal links
Proposals and vendor requests are served from hosted pages reached through long, randomly generated links that cannot be guessed. Links can carry an expiry date and can be revoked by the sender at any time, after which the page stops working. Sensitive proposals can require the recipient to confirm their email address with a one-time code before the proposal is shown. A person who receives a link can still forward it, so we present activity from unverified sessions as unidentified rather than as a named person.
2. Authentication and access controls
Accounts sign in with email and password or with Google. Sessions are managed by our authentication provider, and every request to private data is re-checked on the server rather than trusted from the browser. Hiding a page from navigation is never used as a security control.
3. Role-based workspace permissions
Data is scoped to a workspace, and roles (owner, admin, member, viewer) govern what a person can do. Project collaborators are invited as viewers, collaborators or decision makers. Database row-level security enforces these boundaries in the database itself, so a request outside your workspace returns nothing.
4. Encryption in transit
All traffic to the application, its API and document storage is served over HTTPS with modern TLS. Email is sent over authenticated channels from our verified sending domain with SPF, DKIM and DMARC in place.
5. Storage and processing safeguards
ReplyToQuote uses third-party infrastructure providers to store and process information. We use administrative, technical and organizational safeguards designed to protect stored and transmitted data. Additional information about relevant security practices may be made available where appropriate.
- Encryption in transit — All traffic to ReplyToQuote is served over HTTPS (TLS) with HTTP Strict Transport Security enabled, and the application's connections to its database are encrypted.
- Hosting provider — ReplyToQuote runs on Cloudflare's global edge network.
- Database provider — Application data is kept in a managed PostgreSQL 17 database with managed object storage. Uploaded files are stored in private buckets that are not publicly readable.
- Email provider — Automated email is sent through a dedicated transactional email service from the authenticated sending domain notify.replytoquote.com. Contact addresses at replytoquote.com are inbound mailboxes handled separately.
- Analytics provider — ReplyToQuote does not load third-party analytics, advertising or tag-manager scripts. Product usage is recorded only in our own database.
6. Document-access controls
Uploaded proposals and project files live in private storage that is not publicly readable. Files are served through short-lived authorized links generated only for people with permission to see them. A file that has been downloaded leaves the service, and we cannot control it after that point.
7. Infrastructure and service providers
- Edge application hosting (Cloudflare network) — Application hosting and content delivery.
- PostgreSQL database and object storage — Database, authentication and document storage.
- Transactional email service (sending domain notify.replytoquote.com) — Delivery of transactional email such as proposal links and notifications.
8. Logging and monitoring
Authorization events, proposal and vendor activity, and email delivery outcomes are recorded in an internal audit log with UTC timestamps. Administrators have an internal review panel that reads live checks against the database rather than a static report. Application and platform errors are captured for diagnosis.
9. Secure software-development practices
Changes are reviewed before release, database changes are applied as versioned migrations, and secrets are stored as server-side environment values that are never exposed to the browser. Database security checks run against the schema, and we review permission policies when tables change.
10. Incident response
If we become aware of an incident affecting your information, we investigate, contain and remediate, and we notify affected customers and regulators where the law requires it. Notices go to workspace owners by email.
11. Data retention and deletion
Information is kept while an account is active and while needed for service, legal and accounting purposes; after that it is deleted or anonymized. See the Privacy Policy for details and for how to make a deletion request.
12. Reporting a vulnerability
Send security reports to support@replytoquote.com. Please include enough detail to reproduce the issue, and give us a reasonable period to investigate before public disclosure.
Keep full exploit details out of any other channel so the report is handled by the security route only. We do not operate a paid bounty programme today, and we will acknowledge researchers who report responsibly.
Report a security concern
Email support@replytoquote.com. For anything else, use the contact form.
