Security is a shared responsibility between Repute and each customer organization. This overview explains the controls currently used to protect customer and visitor information.
Role-Based Access
Access is controlled according to the user's organization, role, account state and assigned buildings. Customer roles include organization leads and administrators, building managers, and front-desk or security staff.
Organization leads and administrators can manage users, buildings and permissions within their organization. Building managers and staff receive access according to assigned responsibilities. Customers can separately enable or disable whether a guard may view recent logbook records they checked in or checked out; visitor logging and checkout remain separate operational permissions. Repute platform operators do not have routine visitor-record retrieval or export access.
Account Protection
Public signup is disabled. Accounts are provisioned by authorized operators and customer administrators. Generated temporary passwords are shown only at creation or reset time and are not stored recoverably.
Password reset, account pause, termination and sign-out workflows revoke affected sessions. Repute may restrict or suspend access where unauthorized activity, misuse, payment failure, organization hold or another security risk is suspected.
Visitor Records and Encryption
Sensitive visitor-log fields receive authenticated application-layer encryption before database storage. Protected fields include every customer-configured custom value, visitor name, document number, visitor phone parts, destination and purpose notes, checkout feedback, and private document-image object keys. Encryption of custom values is mandatory and cannot be disabled. Customer-configured yes/no and single-select custom fields are automatically available as exact-match filters, and those filters use separately keyed blind indexes rather than plaintext values.
The encryption implementation uses AES-256-GCM with server-side key material and field-specific authenticated additional data. Managed providers may also apply infrastructure-level encryption, but Repute's strongest product-level claim is the application-layer encryption implemented in the service.
Identification Images
Submitted identification images are stored as private objects. Access is controlled through the application according to organization, role and building permissions, and may use temporary signed access where needed.
Customers should collect only the information needed for their operations and avoid downloading, copying or sharing identification images unless there is a legitimate and authorized reason.
Document Scanning
The Repute mobile app may use on-device optical character recognition to extract a name and number from the front of an Emirates ID. Extracted information may not always be complete or accurate, so users must review it before saving. Manual entry remains available, and identity images are not sent to an LLM.
Audit Records
Repute maintains activity records for sensitive account, organization, building, billing, assignment, visitor-export, certificate and lifecycle actions. These records support accountability, administration, troubleshooting and security review.
Audit records intentionally avoid raw visitor PII such as generated passwords, visitor names, visitor document values and raw identity-document data.
Technical Monitoring and Infrastructure
Repute records limited technical information needed to identify errors, investigate service issues, detect suspicious activity and protect the platform. Telemetry sanitization redacts sensitive values such as authorization headers, cookies, emails, names, passwords, session tokens, document values, phone/contact values, private image references and exception messages.
Production runtime database access uses least-privileged credentials and automated checks for expected privileges. Repute may use trusted providers for hosting, deployment, database storage, private object storage, authentication, email, payment processing, mobile build tooling, monitoring and customer support. Access is limited according to operational requirements.
Backups and Recovery
Repute may maintain backups and operational copies for service continuity, recovery and security. Recovery depends on the relevant configuration, provider capabilities and circumstances of the incident. Customers should export important records according to their own operational and retention requirements.
Customer Responsibilities
Customers should:
- Collect only visitor data needed for building operations
- Limit administrative access and review user accounts regularly
- Remove former staff promptly
- Train managers and front-desk users
- Secure shared devices and protect exported records
- Keep devices and browsers updated
- Provide visitor notices and legal basis appropriate to their building
- Maintain an alternative visitor-entry process during service interruptions
- Report suspected security incidents promptly
Repute cannot control or protect information after it has been downloaded, copied or shared outside the platform.
Security Incidents
Where Repute becomes aware of a security incident affecting customer information, we will investigate, take reasonable containment and remediation steps, preserve relevant evidence, and coordinate customer communications according to the agreement, customer instructions and applicable law. Customers should keep contact details current so important security communications can be received.
Compliance Position
Repute provides product controls that may help customers implement parts of their own data-protection program, including purpose-focused configuration, role-based access, data minimization, retention limits, security controls and customer-responsibility separation. These controls are not a certification, legal opinion or guarantee of compliance with the UAE PDPL or any other law.
Customers remain responsible for their notices, legal basis, internal policies and operational use of records.
Reporting a Security Concern
Security concerns should be reported privately to hello@repute.ae with enough information for us to understand and investigate the issue. Unauthorized security testing, automated scanning or attempts to access customer information are prohibited.
Security Limitations
No online platform can guarantee complete security or uninterrupted availability. Customers remain responsible for deciding whether Repute's security controls are suitable for their operational requirements.