Security and trust

Your sellers’ hardest deals. Nobody else’s business.

Replicate Labs is independently audited, penetration tested by a CREST certified team, and built so that your data is technically isolated from every other customer. It is never used to train a model. Here is the evidence, and the pack behind it.

  • SOC 2 Type 2
  • Pentest grade A+
  • UK or US data residency
  • No model training

Last independently reviewed 31 July 2026

Keenan, Caty and Val on how we handle your data · 46 seconds
SOC 2 Type 2INTERCERT CPA LLC · Security, Availability, Confidentiality
Penetration test, grade A+Astra Security · certificate valid to 4 August 2027
UK GDPRUK headquartered · London data residency · DPA with named sub-processors
The attestations

Two independent examinations.

Both are reports an outside firm wrote and signed, available to your security team under NDA. The third card is our legal position, written into the DPA.

Independent service auditor

SOC 2 Type 2

Type 1 tests whether controls are designed properly. Type 2 tests whether they operated effectively across a monitored period. This is the Type 2.

Auditor
INTERCERT CPA LLC
Period
2 March to 8 July 2026
Criteria
Security, Availability, Confidentiality
Opinion
Clean, with no exceptions raised, on all three points

Status: Final report issued 10 August 2026, available to your security team under NDA.

Offensive testing

Penetration test

A manual pentest by human analysts, run alongside an automated scan of more than 10,000 tests, against the live production application.

Firm
Astra Security, CREST certified and CERT-In empanelled
Window
22 to 31 July 2026
Standards
OWASP WSTG, OWASP Top 10, OWASP ASVS, NIST 800-115
Grade
A+, certificate valid to 4 August 2027

The certificate carries a public ID and can be verified directly with Astra.

Data protection

UK GDPR

Handle Technologies Ltd, trading as Replicate Labs, is UK headquartered and processes personal data as a processor under UK GDPR.

Residency
United Kingdom by default; a US region is available on request
Transfers
Standard contractual clauses plus the UK Addendum
Contract
DPA with the full sub-processor list at Annex 2
Changes
14 days’ notice before any new sub-processor, with a right to object

The plain English data page sits alongside the DPA, so you can read it without a lawyer.

Secure by design

The independent assessments validate the controls. The architecture is the real answer.

An audit tells you a company follows its own rules. It does not tell you how the product was built. These four decisions were made before any auditor arrived.

  • 01
    Accounts are walled off from each other

    Isolation is at the company level, enforced in the application code. One customer’s data cannot be reached through the application by another. A coach configured for your account cannot see a conversation, a call, a deal or a document from anyone else’s.

    Inside an account, access is role based and least privilege. Where a parent organisation runs multiple brands, each brand is scoped to its own team so that one brand’s sellers never see another’s material.

  • 02
    Nothing you do trains a model

    Customer data is not used to fine-tune a large language model. That is contracted with the providers behind the coaching, and the DPA codifies it.

    The coaching works by retrieval and inference against your own material at the moment you ask. Nothing is baked into weights, nothing becomes a derivative product, and it does not cross into another customer’s answers.

  • 03
    Your data has a documented address

    The platform and its primary database run in the London region by default. Where a customer needs its primary data held in the United States, a US region is available on request. Either way it sits inside a private network with deny by default firewall rules, and a WAF and DDoS layer in front.

    Encrypted with TLS in transit and AES-256 at rest, backed up daily to encrypted storage with access limited to named personnel. Replicate Labs runs no data centres of its own.

  • 04
    Every sub-processor is named

    There is no quiet list. Each third party that touches data, and what it does, is set out in Annex 2 of the DPA, with its location and its processing role.

    Before a new one is added you get 14 days’ notice with detail on what it will process, and a contractual right to object on data protection grounds.

Your account
User AKeenan
User AVal
User BCaty
User CCaty
User CKeenan
User DVal
Bryce · analyticsReads across the six windows. Stops at the wall.
Two boundaries, not one. The account is a wall that nothing crosses. Inside it, each user and coach conversation is a window that other ordinary users do not see.
Day to day

The controls the auditor tested across the period.

These are the operating controls tested across the 2 March to 8 July 2026 window. Eighteen written policies sit behind them, acknowledged by every staff member on hire and every year after.

Access

  • Multi-factor authentication on critical systems
  • Role based, least privilege, with a documented access matrix
  • Access reviewed quarterly by the Information Security Officer
  • Leavers cut off within one business day
  • Background checks on every new hire

Change

  • Peer review mandatory on every code change
  • The reviewer is never the author
  • Automated testing through the CI/CD pipeline
  • Development and test environments logically separated from production
  • Management approval before anything reaches production

Monitoring

  • Continuous compliance monitoring across systems and controls
  • Vulnerability scanning at least monthly, including open source dependencies
  • Penetration testing annually, and after any material change
  • Audit events generated for security relevant actions
  • Findings risk ranked and tracked to closure

Resilience

  • Encrypted backups taken at least daily
  • Business continuity plan tested against defined RTOs and RPOs
  • Restores exercised at least annually
  • Backup access limited to named personnel
  • Application, database and storage monitored against service levels

Incidents

  • Defined roles, escalation paths and customer communication
  • Four severity tiers, from low through to critical
  • Security alerts reviewed and analysed for anomalous activity
  • Post-mortems mandatory on every critical incident
  • A named support route for customers to raise one

People

  • Confidentiality agreement signed on hire
  • Security awareness training on hire and annually
  • Eighteen policies acknowledged annually, from encryption to media disposal
  • Code of business conduct, with sanctions up to termination
  • Termination checklist covering every system
The awkward questions

Three things a security team always asks.

Answered the way we would answer them on the call, including the part most vendors leave out.

Where does it sit

The United Kingdom by default. The United States on request.

The platform and the primary database run in the London region as standard. If your organisation needs its primary data held in the United States, say so and we will provision you in a US region instead. The cloud provider is treated as a carved out sub-service organisation either way, so its physical and environmental controls are reviewed annually against its own attestations.

The one thing worth saying plainly: AI inference calls reach US infrastructure. For a UK hosted customer that is an international transfer, made under standard contractual clauses and the UK Addendum, the standard contractual framework for UK to US transfers. We do not bury that. It is documented, and the full path is set out in the DPA.

Who touches it

Every sub-processor is named, with notice before it changes.

The full list, with location and processing role, is at Annex 2 of the DPA. It covers the AI, transcription, voice, vector search, billing, identity, support and error monitoring services behind the product. Nothing sits outside it.

Adding one takes 14 days’ notice to customers, with detail on what it will process and a right to object on data protection grounds.

What you never do

Your sellers’ work does not train anyone’s model.

No customer data is used to fine-tune a large language model, ours or a provider’s. It is not sold, not shared with other customers, and not turned into a derivative product. Coaching runs on inference against your data, and then your data stays yours.

Data is classified, all customer data is treated as confidential, and retention follows the written data retention policy.

The security review pack

Let your security team do a proper review before you commit.

Everything an assessment needs, in one pack, available under NDA. Ask your Replicate Labs contact and it comes back the same week.

The plain English data page and the DPA are readable now, without an NDA.
  • SOC 2 Type 2 report, in full
  • Penetration test report and certificate
  • Network and application architecture
  • Data Processing Agreement and sub-processor list
  • Written security policy set
Request the review pack

Replicate Labs is a trading name of Handle Technologies Ltd, a company registered in the United Kingdom. The SOC 2 Type 2 examination was performed by INTERCERT CPA LLC for the period 2 March 2026 to 8 July 2026; the report is available under NDA and remains subject to its own restricted use terms. Penetration testing was performed by Astra Security between 22 and 31 July 2026. This page summarises those reports and is not a substitute for them. These reports describe the platform as tested and do not, on their own, constitute a warranty. Correct as at 10 August 2026.