Security
Security at ReviewJet
ReviewJet handles your customer contacts and review data. This page describes exactly how that data is encrypted, where it lives, who can access it, and which guarantees Enterprise plans add. If your procurement team needs more, email app@reviewjet.com.
Encryption
Encrypted in transit and at rest
In transit: TLS 1.2+
All traffic between your browser, our widget script, our API and our servers is encrypted with TLS 1.2 or higher. Plain HTTP is refused and HSTS is enforced on all ReviewJet domains. Internal service-to-service traffic inside our VPC is encrypted as well.
At rest: AES-256
Databases, file storage and backups are encrypted at rest with AES-256 using AWS-managed keys. Backups are taken daily, stored encrypted in a separate availability zone, and tested for restorability every quarter.
Access control
SSO, roles and audit logs
Available on the Enterprise plan.
SSO / SAML 2.0
Sign in through Okta, Microsoft Entra ID, Google Workspace or any SAML 2.0 identity provider. SCIM-based deprovisioning removes access the moment someone leaves your directory.
Roles & permissions
Admin, editor and viewer roles per workspace. Editors moderate reviews and edit widgets; viewers see analytics only. Permission changes take effect immediately.
Audit log
Every sign-in, permission change, widget edit and review moderation action is recorded with actor, timestamp and IP, retained for 12 months and exportable as CSV.
Compliance
GDPR, DPA and data residency
GDPR and DPA
For the customer data you bring into ReviewJet, we act as a processor and you remain the controller. A Data Processing Agreement incorporating the EU Standard Contractual Clauses is available on request from app@reviewjet.com. Data subject requests, including export and deletion, are completed within 30 days.
EU or US data residency
Choose where your workspace data is stored when you create it: AWS us-east-1 (N. Virginia) or AWS eu-central-1 (Frankfurt). Review content, contact lists, backups and logs stay in the selected region. Residency can be changed later through a supported migration.
Subprocessors
Who touches your data, and why
The complete list. We notify DPA holders 30 days before adding a subprocessor.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services | Hosting, databases, backups | All workspace data, encrypted | us-east-1 or eu-central-1, per workspace |
| Postmark | Transactional email delivery (review requests, confirmation codes) | Recipient email addresses, message content | United States |
| Cloudflare | CDN for the widget script, DNS, DDoS protection | Visitor IP addresses in transit; no stored personal data | Global edge network |
Availability and SLA
The widget is served from Cloudflare's edge and degrades gracefully: if our API is ever unreachable, your page renders normally without the widget, never with a broken block. Enterprise plans carry a contractual 99.9% monthly uptime SLA with service credits.
Responsible disclosure
Found a vulnerability? Email security@reviewjet.com with reproduction steps. We acknowledge reports within 2 business days, keep you informed through the fix, and credit researchers who wish to be named. Please do not test against other customers' data.
Need a security questionnaire completed, a penetration test summary, or a custom review? Enterprise plans include a full security review with our team.
Talk to sales