Home / Security
Security and trust

Designed for confidential brand evidence.

Every submission is protected by private storage, verified payments, authenticated access and an auditable manual-review workflow.

Encrypted in transit and at restLeast-privilege accessHuman-reviewed, always
Data handling

Your evidence is treated as confidential from the moment it arrives.

Every order, project, message, score and report is tied to your authenticated account and visible only to you and the reviewer assigned to your work. Uploaded files move directly into private storage and are never shared outside your organisation without permission.

Payment details are collected directly by Stripe. ReBrandMyAI never sees or stores raw card numbers.

Production controls

The security model behind rebrandmyai.com.

Security is applied across identity, payments, files, projects, reviewer access, report release and operational monitoring.

01

Verified payments

Stripe collects payment data. A signed backend webhook, not a browser redirect, creates the paid order and project.

02

Private evidence storage

Files upload directly to private cloud storage through short-lived permissions, enter quarantine and are scanned before reviewer access.

03

Project-level access

Every request checks the authenticated user, organisation membership, role and permission to the specific project resource.

04

Encryption and audit history

Data is encrypted in transit and at rest. Important payment, access, score, QA and publication events are recorded.

05

Internal MFA

Reviewer, QA and administrator accounts require multi-factor authentication and shorter authenticated sessions.

06

Least privilege

Reviewers see assigned work. Finance, QA and administration permissions remain separate rather than sharing one powerful account.

07

Monitoring and recovery

Operational errors, suspicious activity, backup health and high-risk changes are monitored with tested recovery procedures.

08

Environment separation

Development, staging and production use separate data, credentials, storage, identities and payment modes.

Experience Integrity access

We request access, not secrets.

Technical verification may require visibility into the implementation supporting an agreed experience. The operating model is invitation-based, least-privilege and time-bounded wherever the provider allows it.

01 / INVITE

Prefer controlled roles

Read-only repository collaboration, restricted cloud viewer roles, test-mode payment access and scoped log visibility are preferred over shared credentials.

02 / MINIMISE

Only what the experience needs

Technical access is limited to resources materially supporting the agreed experiences. Unrelated systems are not explored as part of the review.

03 / REMOVE

Close access after the work

Access should be removed when the report and included recheck window no longer require it. Production secrets must never be pasted into normal intake or message fields.

Manual-review integrity

Templates support consistency. Humans remain accountable for the judgment.

Each client-visible score, observation, evidence statement, commercial consequence and recommendation must be reviewed against the customer’s actual materials. Drafting, quality assurance and report publication are separate recorded stages.

A

Evidence-specific

Findings identify where the issue was observed and which submitted material supports the conclusion.

B

Quality controlled

Reports are checked for specificity, evidence, internal consistency, factual details and proportionate recommendations.

C

Versioned release

A published report is preserved. Corrections create a new version rather than silently changing what the client received.

Responsible disclosure

Tell us if something does not look right.

If you believe you have identified a security or privacy concern, contact ReBrandMyAI with the affected page, the behaviour observed and enough detail for us to investigate without sending unnecessary sensitive information.

Report a concern →