/ Security

Security posture, on the record.

Replicost handles sensitive property data, valuation work product, and litigation-related artifacts. Here's how we protect it — and what we're still working on.

SOC 2 Type II — in progress TLS 1.3 / AES-256 RBAC
/ / Today

What's in place.

Encryption in transit

TLS 1.3 for all client traffic. Internal service-to-service traffic uses mTLS.

Encryption at rest

AES-256 on all stored data — production database, object storage, and backups.

Role-based access control

Least-privilege roles for every employee. SSO support (SAML/OIDC) on Enterprise.

Audit logs

Every read, write, and admin action is logged and exportable. Workfile-relevant access trails are kept indefinitely.

Vulnerability management

Continuous dependency scanning, penetration tests at least annually, bug-bounty program for security researchers.

Backups & DR

Point-in-time backups, geo-redundant. Documented recovery time and recovery point objectives.

/ / In progress

What we're working on.

Independent attestations take time. Here's where we are in the queue.

/ IN PROGRESS

SOC 2 Type II

Type I attestation expected later this year, Type II to follow with a full observation window. We are not yet SOC 2 certified. We will say so plainly until we are.

/ IN PROGRESS

ISO 27001

Targeted for the year following SOC 2 Type II. The two attestations share enough overlap that they're practical to sequence.

/ / Contact security

If you found something.

Security researchers, responsible disclosures, and customer security reviewers — please email security@replicost.com. We respond to all reports within two business days and operate a coordinated-disclosure program.

/ Ready when you are

Request the security packet.

Enterprise prospects: ask us for the security questionnaire, sub-processor list, and DPA. We will not pretend to attestations we don't hold.

EST. 2014 · LITIGATION PROVEN · USPAP-COMPLIANT