Security you can hand to your CISO
Last updated July 2026
RepCue is sold to VPs of Sales and CISOs, not smuggled past them. This is a summary of our security posture; the binding documentation (security questionnaire, DPA, subprocessor list) is available on request during your pilot.
Consent by design
A jurisdiction-aware consent engine infers participant regions and enforces the strict reading by default: one-party where permitted, two-party disclosure where required, assist-only mode where audio must never be stored.
Assist-only mode
Audio → transcription → suggestions, all in memory. No call audio is persisted, ever. Transcript TTL is roughly the call duration; only derived aggregates are retained. This is the wedge for strict-consent jurisdictions.
Data protection
TLS in transit and AES-256 encryption at rest. Your data is deleted on request, and per-org retention windows are configurable in the admin console. We do not train foundation models on your data, and we work with model and ASR providers under terms that restrict use of your data.
Compliance roadmap
SOC 2 Type I underway, Type II to follow; GDPR (DPA, SCCs, EU residency) at EU launch; HIPAA-ready configuration for health-adjacent sales. Annual pentest and a private bug bounty.
Questions? Get in touch or return to the homepage.