Security · privacy · compliance

Security built for enterprise scrutiny

ReplyFabric processes business-critical email with independently verified controls, EU data residency, strict access management, human oversight and an auditable record of every AI-assisted workflow.

ISO 27001 Certified. SOC 2 Type II Certified. EU-first by design.

Visit Trust Center

Independent assurance

Verified controls, not security promises

ReplyFabric combines certified governance with technical and operational controls designed for AI-assisted shared mailbox processing.

01

ISO/IEC 27001

Certified

Our Information Security Management System is independently certified against the international standard for managing information security risk.

02

SOC 2 Type II

Certified

Our operational controls were independently examined over the period from 1 March through 30 June 2026.

03

Data residency

European Union

Customer email data, AI processing and audit records are processed and stored on EU-resident infrastructure.

Security at a glance

Controls procurement teams can evaluate

The controls below cover the complete workflow: how data is protected, where it is processed, who can access it, what AI may do, and how every outcome can be reviewed.

TLS 1.2+ + AES-256

Encryption

Customer data is protected in transit and at rest, including during the email automation workflow.

RBAC · SSO · MFA

Identity & access

Role-based access, least-privilege permissions and strong authentication restrict access to authorized users.

EU processing & storage

Data location

Core customer data stays inside the European Union, reducing international transfer complexity.

Approval before send

Human control

AI categorizes, routes and drafts; a person remains responsible for customer-facing AI replies and consequential actions.

Traceable decisions

Auditability

Processing events, AI suggestions, sources, human edits and final actions are recorded for review.

Minimised & configurable

Data lifecycle

Only data required for the workflow is processed, with configurable retention and deletion on request.

Data flow & audit trail

Traceability from receipt to final action

ReplyFabric creates a reviewable sequence for each email. The system records the processing step, supporting evidence and human action instead of leaving decisions inside a black box.

01

Email received

The message is received, identified and timestamped.

Message IDTimestamp
02

Categorized

The category, confidence and relevant decision signals are captured.

CategoryConfidenceSignals
03

Routed

The responsible team or person is selected using the configured workflow.

RuleResponsible
04

Draft generated

The AI prepares a response using approved knowledge and relevant context.

ModelSourcesPrompt
05

Human review

A named reviewer can edit, approve or reject the proposed response.

ReviewerChangesAction
06

Final action

The approved response and final workflow action are recorded.

Final outputStatus

Quick Answer

Can ReplyFabric explain what happened to an individual email?

Yes. Categorization, routing, source-grounded drafting, human review and the final workflow action are recorded so the processing history can be reviewed and explained.

Privacy by design

GDPR safeguards built into the workflow

Shared mailboxes routinely contain personal, contractual, financial and business-sensitive information. ReplyFabric limits processing to defined purposes, controlled users and reviewable actions.

The operating principle

AI can prepare. Humans approve.

AI may analyze, categorize, route, retrieve context and draft. A person retains control over customer-facing communication and can edit, approve or reject the proposed output.

Purpose limitation

Email content is processed for defined mailbox workflows, not repurposed for unrelated activities.

Data minimisation

The workflow processes only the data needed to categorize, route, retrieve context or prepare a reply.

Controlled access

Permissions determine who can access mailboxes, queues, knowledge, settings and generated drafts.

Transparency

Teams can review what the AI suggested, which sources informed it and what a person changed.

Human oversight

Outbound communication remains under human control, supporting accountability and reviewability.

Retention & deletion

Retention can be configured for the deployment, and customer data can be deleted on request.

Security governance

Secure by design and disciplined in operation

Technical safeguards are supported by formal governance, continuous monitoring, documented evidence and independent assessment.

Risk management

Security risks are identified, assessed and treated through a documented Information Security Management System.

Policies & evidence

Security controls are supported by documented policies, assigned responsibilities and traceable evidence.

Continuous monitoring

Control performance is monitored in operation and reviewed as systems, risks and requirements change.

Independent assurance

External auditors assess both the security management system and the operation of relevant controls.

Procurement package

Evidence for your security review

Enterprise customers and qualified prospects can request the documentation needed for procurement, information security review and data-protection due diligence.

Visit the ReplyFabric Trust Center
  • ISO/IEC 27001 certificate
  • SOC 2 Type II report
  • Data Processing Agreement (DPA)
  • Records of Processing Activities (RoPA)
  • Security and architecture information
  • Data retention and deletion information
  • Subprocessor and AI processing-flow review
  • Service Level Agreement options

Frequently asked questions

Answers for security and procurement teams

A concise summary of ReplyFabric's security posture, assurance, data handling and deployment scope.

01

Where does ReplyFabric process and store customer data?

ReplyFabric processes and stores customer email data, AI processing records and audit information on infrastructure located within the European Union. This EU-first architecture reduces the international transfer complexity associated with core processing.

02

Is ReplyFabric independently certified?

Yes. ReplyFabric is ISO/IEC 27001 and SOC 2 Type II certified. The ISO/IEC 27001 certification covers our Information Security Management System, while the SOC 2 Type II examination assessed the operation of relevant controls over the period from 1 March through 30 June 2026.

03

Is SOC 2 technically a certification?

SOC 2 is commonly described as a certification. Technically, it is an independent attestation examination that results in a SOC 2 report. When we say ReplyFabric is SOC 2 Type II certified, we mean that an independent auditor examined our controls over a defined period and issued the final report — it is not a self-declared compliance claim.

04

How is access to mailbox data controlled?

ReplyFabric uses role-based access control, least-privilege permissions, SSO and MFA. Access events are recorded so organizations can review who accessed the system and what actions were taken.

05

Can ReplyFabric send AI-generated replies automatically?

ReplyFabric is designed around human-in-the-loop control. AI can categorize, route, retrieve context and prepare a draft, but customer-facing replies remain subject to human review and approval.

06

Can customers define retention and request deletion?

Yes. Enterprise deployments support configurable data-retention and deletion policies. ReplyFabric also supports customer requests relating to deletion and data-subject rights as part of its GDPR processes.

07

What documentation is available for a security review?

Qualified prospects and customers can request the ISO/IEC 27001 certificate, SOC 2 Type II report, DPA, RoPA, security and architecture information, retention details, and a review of relevant subprocessors and AI processing flows.

08

Is ReplyFabric HIPAA compliant?

ReplyFabric is designed primarily for organizations operating under GDPR and is not currently marketed as HIPAA compliant. Healthcare or other highly regulated deployments are assessed and scoped individually, including the required contractual, infrastructure and processing controls.

Ready for your security review?

Request our certification evidence, SOC 2 Type II report, DPA and supporting security documentation.

14-day free trial
No credit card required
Cancel anytime