Security, resilience and AI governance
Last updated 30 August 2026
RepeatProof is an intelligence layer—not a replacement for a controlled quality system or professional judgement. This page describes implemented product controls and the evidence we can provide. It does not imply a certification, legal conclusion or control that has not been configured for a specific customer.
Architecture and customer boundary
- Separated workspaces: tenant membership and row-level database policies restrict customer records to authorised workspace members.
- Customer-controlled option: a customer may retain records in its own approved data plane and run outbound, read-only connectors in its environment.
- Least data: pilots begin with a bounded historical export or agreed read-only source. Credentials stay in the deployment secret manager, not connector records.
- Authoritative system: the customer's QMS and named people remain authoritative for root cause, disposition, release, conformity and closure.
Identity and access
Supabase authentication, tenant roles and server-side entitlement checks protect the application. Each customer Assurance register records MFA policy and enforcement, SSO protocol and state, SCIM state, verified domains and session target. Enterprise identity is shown as “not configured” until the relevant provider is tested and activated; the public website does not claim universal SSO or SCIM deployment.
Data protection and lifecycle
- Transit and storage: production providers are required to protect data in transit and at rest; exact region, provider and customer-controlled key boundary are agreed for the engagement.
- Residency: the configured hosting region is recorded per workspace. Marketing wording does not override the contracted location.
- Retention and deletion: purpose, fields, retention window, deletion instruction and backup boundary are agreed before exchange. Customer administrators retain an auditable deletion control.
- Backups: owner, recovery-point target, recovery-time target and restore-test evidence are recorded per customer rather than inferred from a generic platform claim.
AI and model governance
External AI interpretation is off unless both the engagement control and an authorised user approve the individual run. Only a minimised calculated-evidence package is sent; raw files and direct record identifiers remain in the customer workspace. Engine, prompt and benchmark versions are recorded. CAPA, Inspection and Audit releases are blocked by evidence-traceability, decision-boundary, confidence/limitations and deterministic-repeat checks. See the versioned evaluation record.
Secure delivery and monitoring
Changes pass locked dependency installation, unit and agent-benchmark tests, a production build, controlled browser journeys and accessibility checks on Node 22. Production promotion is a separate protected action that deploys the verified prebuilt artifact. Application failures carry request identifiers and structured server logs; current reachability is shown on the service status page. Historical availability is not claimed until measurement history exists.
Incident response and resilience
Customers can report issues directly through Sentinel in the secure workspace. The response process preserves deployment, request and audit evidence; assigns severity and an accountable lead; and records containment, recovery, communications and corrective actions. Customer-specific incident contacts and recovery targets are visible in Workspace Setup → Assurance.
Standards and regulatory mapping
The due-diligence pack maps relevant controls to OWASP ASVS, NIST AI RMF, ISO/IEC 42001 concepts, EU AI Act governance themes and WCAG 2.2 AA criteria. These mappings support assessment and gap review; they are not certificates or legal advice. Any certification or formal conformity statement must come from the relevant accredited body or qualified adviser.
Subprocessors and integrations
The current provider register is maintained on the subprocessors page. The integration catalogue distinguishes supported reference adapters from customer-specific discovery. No unverified vendor certification is implied.
Due-diligence pack
Prospective customers can request the data-processing agreement, architecture and data-flow summary, role/access matrix, retention/deletion schedule, model-processing description, release and incident runbooks, current subprocessor list and security questionnaire response. External penetration-test or certification evidence is supplied only when it exists and its sharing terms permit it.
Request a scoped assurance review or contact the RepeatProof security team.
Responsible disclosure
Report a suspected vulnerability privately through the RepeatProof security team. Include enough detail to reproduce the issue and do not access data that is not yours.