generated: '2026-07-26' method: searched probe: false probe_note: >- 0-working/probe-security-programs.py returned "trust=none" — there is no trust.reapit.com, no /trust and no /compliance path. The security posture is published on a marketing product page instead, which the keyword-threshold probe does not treat as a trust center. Recorded here from a direct read of that page. url: https://www.reapit.com/security status: 200 title: Security — Keep yours and your clients data safe description: >- Reapit publishes its security posture on a product page under Platform > Infrastructure > Security rather than in a dedicated trust center. The substantive, verifiable claim is ISO 27001 certification with independent third-party audits, backed by an Information Security Management System framework. Single sign-on across the platform and partner integrations, and multi-factor authentication, are named controls. There is no downloadable evidence portal, no SOC 2 report, no sub-processor list, no status-of-controls page and no security questionnaire self-service — so buyers must ask for evidence through sales or the partner team. certifications: - name: ISO 27001 status: certified scope_note: >- "Externally audited ISO 27001 accreditation" covering Reapit's Information Management Security System framework of practices, policies and controls. evidence_url: https://www.reapit.com/security independently_audited: true controls_published: - name: Information Security Management System (ISMS) detail: framework bringing together practices, policies and controls - name: Single sign-on detail: one secure login across the Reapit platform and partner integrations - name: Multi-factor authentication detail: named as a platform control - name: User and client authentication / access permissions detail: >- Per-customer app install grants scoped permissions; uninstall revokes access (see scopes/reapit-scopes.yml) - name: Webhook payload signing detail: Ed25519 asymmetric signing with per-app key pairs - name: Published webhook egress IPs detail: three static eu-west-2 Elastic IPs for firewall allowlisting - name: App listing review detail: >- Every AppMarket application passes a Reapit listing review before it can reach any customer's production data not_published: - SOC 2 Type I or Type II report - PCI DSS attestation - HIPAA / FedRAMP (not applicable to this market) - CSA STAR listing - sub-processor list - public penetration-test summary - security questionnaire self-service / evidence portal - RFC 9116 security.txt related_pages: privacy_policy: https://www.reapit.com/legal/privacy-policy cookie_policy: https://www.reapit.com/legal/cookie-policy modern_slavery: https://www.reapit.com/legal/modern-slavery-policy terms: https://www.reapit.com/legal/terms-and-conditions developer_terms: https://foundations-documentation.reapit.cloud/developer-terms-and-conditions partner_bsc: https://www.reapit.com/legal/terms-and-conditions/reapit-partner-business-service-catalogue status: https://status.reapit.com/ evidence: - source: https://www.reapit.com/security keywords: [iso 27001, independent third-party audits, information management security system, single sign on, multi factor authentication] fetched: '2026-07-26'