Security at XreplyAI

Last Updated: September 22, 2026

XreplyAI holds the keys to your social accounts. This page describes what we do to protect them and the rest of your data. Every statement here describes something we run today. Where we have not done something, we say so.

For what data we collect and why, see the Privacy Policy.

1. Encryption

  • In transit: Every connection to xreplyai.com, the API, and the MCP server uses HTTPS with TLS. Plain HTTP is redirected.
  • At rest: Social platform OAuth tokens, refresh tokens, API keys, and other stored credentials are encrypted in the database with AES-256-GCM before they are written. The encryption keys are held outside the database.
  • Backups and media: Database backups and uploaded media are stored in Cloudflare R2, which encrypts objects at rest. The backup bucket is private and has no public access.

2. Hosting and Infrastructure

  • Application and database: Railway, in the United States.
  • Website and dashboard: Vercel.
  • Media, backups, and the MCP server: Cloudflare (R2 storage and Workers).
  • Payments: Stripe, a PCI DSS Level 1 processor. Card numbers never touch our servers.

Each provider runs its own certified data centers and physical security. We do not operate hardware ourselves.

3. Sign-in and Sessions

  • Sign-in is by a one-time code sent to your email, by password if you set one, or with Google.
  • Passwords are stored only as salted hashes and are never logged.
  • Sign-up and sign-in are protected by Cloudflare Turnstile, an invisible bot check verified on our servers before an account is created or a code is sent.
  • Sessions are signed tokens that expire on their own. Deleting your account revokes every session immediately, and we can revoke all sessions for an account on request.

4. Access Control

  • Workspace roles: Owner, admin, member, and viewer. Viewers cannot change anything. Only the owner can top up the AI balance or delete the workspace, and only admins can pause automation.
  • Server-side enforcement: Every permission is checked on the server, never only by hiding a button.
  • Internal access: Production data is accessed only to operate the Service or resolve a support request you made, and only by the founder. There is no production shell in day-to-day use; diagnosis runs on logs and metrics.

5. API Keys and the MCP Server

  • API keys are created in Settings, scoped to the permissions you pick, and can be revoked at any time. A revoked key stops working immediately.
  • Keys are stored encrypted and shown to you once, at creation.
  • The hosted MCP server uses OAuth 2.1. Its tools can read your subscription status but can never change billing, see payment details, mint credentials, or reach other users' data.
  • Endpoints that generate content, and sign-up and sign-in, are rate-limited to stop abuse and runaway automations.

6. Backups and Recovery

  • The database is backed up nightly to a private, encrypted bucket. Backups are kept for 30 days.
  • Restores are tested: we have restored a backup into a scratch database and verified record counts against production.
  • A missed backup triggers an alert to the founder.

7. Monitoring and Incident Response

  • Application errors are reported to Sentry and logs are shipped to Datadog, with monitors for error spikes, missed backups, and unresponsive services.
  • If we confirm a breach affecting your personal data, we will notify you by email without undue delay and within the timelines that applicable law requires, and tell you what was affected and what we did.

8. Your Social Accounts

  • We request only the platform permissions the features you use need, and we ask for new permissions when you connect, not silently.
  • Disconnecting an account deletes its tokens from our database immediately. You can also revoke XreplyAI from each platform's own settings.
  • Content waits for your review by default. Automations that publish without review are switches you turn on, per generator, and a single Pause control stops all of them.

9. Data Deletion

You can delete your account yourself from Settings → Account. Deletion removes your content, connected accounts, tokens, media, and brand knowledge immediately, and the data leaves our backups within 30 days. Details, and what we keep for legal reasons, are in the Privacy Policy.

10. Audits and Certifications

We have not completed a SOC 2 or ISO 27001 audit. We are a small company and would rather tell you that than imply otherwise. Our hosting, storage, and payment providers hold their own certifications, and we will link a report here if we complete one.

11. Reporting a Vulnerability

If you find a security problem, email john@xreplyai.com with the subject line "Security". Include what you found, how to reproduce it, and how to reach you. We acknowledge reports within 2 business days, keep you updated while we fix it, and credit you if you want.

Please give us a reasonable time to fix an issue before publishing it, and do not access, modify, or delete data that is not yours while testing. We will not pursue action against researchers who follow these guidelines.

12. Contact

Security questions from customers and prospects: john@xreplyai.com

Back to Home