Redo Security Policy

Last updated July 27th, 2026

Security is part of the product

Redo powers post-purchase experiences for thousands of brands — which means we're handling order data, customer data, and revenue-critical infrastructure every day. We built our security program to match that responsibility, not as an afterthought.

Our Approach

We invest in security the way we invest in the product.

Continuously, and with real engineering behind it. Redo is SOC 2 compliant, audited annually by an independent third party, and our infrastructure is monitored around the clock with an independent penetration test every year. Here's what that looks like in practice:

Encryption everywhere — all data is encrypted in transit (TLS) and at rest (AES-256).

Checked by tools and AI — every change to our app must pass a rigorous testing and review process that includes traditional security tools and complex AI security assessments before it can ship to production.

No card data — payment details are handled entirely by trusted third party integrations; Redo stores none of its own.

Data stays in the U.S. — all customer data is stored in the United States, with access restricted, logged, and monitored.

Continuously scanned — our infrastructure and code are scanned around the clock for vulnerabilities and misconfigurations, and every finding is tracked until it's fixed.

Privacy by design — Redo values the privacy of its users and is fully GDPR and CCPA compliant and more.

View our live security & compliance reports →

Our Trust Center gives you real-time access to our compliance information, policies, and more. This is the fastest way to get what you need for a security review.

Contact Us

If you have questions or concerns about Redo’s security, please contact us at [email protected].

We take every security report seriously. If you believe you've found a vulnerability or issue in Redo's products or infrastructure, we want to hear from you.

We review every report that comes in through this address and will acknowledge receipt. If you've found something real, we'll work with you to understand and fix it. Redo doesn’t currently run a paid bug bounty program and does not pay out bug bounties, but every report is read by a real member of our security team.