Trust

Security at ReplyToQuote

Effective September 22, 2026

We use administrative, technical and organizational safeguards designed to protect information. This page describes controls that are actually implemented today.

We hold no third-party security certification or audit report at this time, and we do not claim any compliance framework we have not completed.

2. Authentication and access controls

Accounts sign in with email and password or with Google. Sessions are managed by our authentication provider, and every request to private data is re-checked on the server rather than trusted from the browser. Hiding a page from navigation is never used as a security control.

3. Role-based workspace permissions

Data is scoped to a workspace, and roles (owner, admin, member, viewer) govern what a person can do. Project collaborators are invited as viewers, collaborators or decision makers. Database row-level security enforces these boundaries in the database itself, so a request outside your workspace returns nothing.

4. Encryption in transit

All traffic to the application, its API and document storage is served over HTTPS with modern TLS. Email is sent over authenticated channels from our verified sending domain with SPF, DKIM and DMARC in place.

5. Storage and processing safeguards

ReplyToQuote uses third-party infrastructure providers to store and process information. We use administrative, technical and organizational safeguards designed to protect stored and transmitted data. Additional information about relevant security practices may be made available where appropriate.

  • Encryption in transitAll traffic to ReplyToQuote is served over HTTPS (TLS) with HTTP Strict Transport Security enabled, and the application's connections to its database are encrypted.
  • Hosting providerReplyToQuote runs on Cloudflare's global edge network.
  • Database providerApplication data is kept in a managed PostgreSQL 17 database with managed object storage. Uploaded files are stored in private buckets that are not publicly readable.
  • Email providerAutomated email is sent through a dedicated transactional email service from the authenticated sending domain notify.replytoquote.com. Contact addresses at replytoquote.com are inbound mailboxes handled separately.
  • Analytics providerReplyToQuote does not load third-party analytics, advertising or tag-manager scripts. Product usage is recorded only in our own database.

6. Document-access controls

Uploaded proposals and project files live in private storage that is not publicly readable. Files are served through short-lived authorized links generated only for people with permission to see them. A file that has been downloaded leaves the service, and we cannot control it after that point.

7. Infrastructure and service providers

  • Edge application hosting (Cloudflare network)Application hosting and content delivery.
  • PostgreSQL database and object storageDatabase, authentication and document storage.
  • Transactional email service (sending domain notify.replytoquote.com)Delivery of transactional email such as proposal links and notifications.

8. Logging and monitoring

Authorization events, proposal and vendor activity, and email delivery outcomes are recorded in an internal audit log with UTC timestamps. Administrators have an internal review panel that reads live checks against the database rather than a static report. Application and platform errors are captured for diagnosis.

9. Secure software-development practices

Changes are reviewed before release, database changes are applied as versioned migrations, and secrets are stored as server-side environment values that are never exposed to the browser. Database security checks run against the schema, and we review permission policies when tables change.

10. Incident response

If we become aware of an incident affecting your information, we investigate, contain and remediate, and we notify affected customers and regulators where the law requires it. Notices go to workspace owners by email.

11. Data retention and deletion

Information is kept while an account is active and while needed for service, legal and accounting purposes; after that it is deleted or anonymized. See the Privacy Policy for details and for how to make a deletion request.

12. Reporting a vulnerability

Send security reports to support@replytoquote.com. Please include enough detail to reproduce the issue, and give us a reasonable period to investigate before public disclosure.

Keep full exploit details out of any other channel so the report is handled by the security route only. We do not operate a paid bounty programme today, and we will acknowledge researchers who report responsibly.

Report a security concern

Email support@replytoquote.com. For anything else, use the contact form.