Security at Repwing

Repwing handles recorded sales conversations, which is some of the most sensitive material a company has. This page says what is actually true today, including where the answer is "not yet".

Tenant isolation

All call, transcript, suggestion and knowledge base data is scoped to your organization. One organization cannot access another organization's data. Isolation is enforced in the database rather than only in application code: the organization is a required column on every data table, and every query is scoped by it.

Encryption and credentials

Data is encrypted in transit. Passwords are hashed and sessions are signed. The Chrome extension authenticates with a per user device token that can be revoked on its own, rather than with a shared password, so removing one laptop's access does not disturb anyone else.

Nothing joins your meeting

Audio is captured on your own machine. No bot is admitted to the call and no participant is added, which means there is no extra account with access to your meeting and nothing for IT to approve.

Shared call reviews

A shared review link is unlisted rather than public. Those pages carry a no index instruction and are excluded from search engines and AI crawlers, because they contain real customer conversations. Treat the link itself as the secret, and delete the share when you are done with it.

Subprocessors

Repwing does not sell personal information.

Retention and deletion

Account and call data is retained for as long as the account is active. Individual calls can be deleted in the app, and organization admins can delete any call in their organization. When an account is closed, associated data is deleted or anonymized within a reasonable period, except where retention is required by law.

Certifications

Repwing does not hold SOC 2, ISO 27001 or any other third party security certification today. It is an early stage product and claiming otherwise would be worth less than telling you plainly. If a certification is a hard requirement for your team, raise it through support so you get a real answer rather than a maybe.

Reporting a problem

If you believe you have found a security issue, report it through support with enough detail to reproduce it. Please do not test against other organizations' data.

Common questions

Where is Repwing call data stored?

Application hosting and the database are provided by Railway. Speech to text and translation are provided by Soniox, and transcript analysis by Anthropic. The full list of subprocessors is in the privacy policy.

Can another company see our calls?

No. Every call, transcript, suggestion and knowledge base entry is scoped to your organization, and no query returns another organization's rows. Sharing a call review produces a link that is not indexed by search engines and is excluded from crawlers.

How long is call data kept?

Account and call data is retained while your account is active. You can delete individual calls in the app, and organization admins can delete any call in the organization. When an account is closed the data is deleted or anonymized within a reasonable period, except where the law requires retention.

Does Repwing have SOC 2 or ISO 27001?

Not today. Repwing is an early stage product and holds no third party security certification. If a certification is a requirement for your team, say so on the support page rather than assuming, because the honest answer today is no.

For the full legal detail on what is collected and why, see the privacy policy.

Coaching that arrives during the call, not after it

Repwing listens to your discovery calls and puts the next question on your phone while you are still in the conversation. Fourteen days free, no card.

Start free trial