Platform Security
Security architecture
ReaperAI uses authenticated client and administrator access, role-based database controls, private document storage, encrypted HTTPS transport, server-side workflow enforcement, rate-limited public submission endpoints, and audit-oriented case records.
Client document handling
Approved uploads are limited by file type and size and are stored in a private client-document bucket. Clients should upload only information necessary for the active service. Never upload passwords, API keys, recovery codes, authentication tokens, or similar secrets.
Account security
Use a unique password for this platform. Do not share portal credentials. Sign out on shared computers and report suspected account compromise promptly.
Responsible reporting
If you believe you found a security problem, use the Contact page and clearly label the subject “Security Report.” Do not include live passwords, authentication tokens, full payment-card numbers, or unnecessary personal information in the initial report. Do not attempt to access data belonging to another person or disrupt platform availability.
Scope
This page describes current practices at a high level and is not a warranty that any system is immune from unauthorized access or service interruption. Security controls are updated as the platform matures.