Skip to main content

Security

The controls we actually run: access control, encryption in transit, file storage, backups, audit records, the AI switch, and what we deliberately do not claim.

Last updated:

Access and authorization

  • Sign-in goes through the central YouReply account; the session cookie is not readable by browser scripts (HttpOnly), carries a SameSite restriction and is sent over HTTPS only in production.
  • Authorization is applied at workspace and role level: admin, researcher, coder and viewer. Queries are scoped to the workspace, so one account's data cannot be read from another workspace.
  • The AI engine is not exposed to the internet; it is reachable only from the server's internal network.

Encryption in transit

  • The marketing site, the application and the account domain are served over HTTPS; HTTP requests are permanently redirected to HTTPS.
  • An HSTS header is sent for two years and covers subdomains; pages cannot be framed by other sites.
  • Certificates are renewed automatically with Let's Encrypt.

Documents and data storage

  • Text extracted from documents, codings and reports are stored in the database, scoped to your workspace.
  • When original uploaded files are kept in object storage they are not publicly accessible: access is only through a short-lived signed URL issued after an authenticated request. File names are generated randomly under an account and study prefix; the original file name is never part of the address.
  • Documents can be deleted permanently from the panel; deletion also covers the extracted text, segments and excerpts.

Backups

  • The database is backed up six times a day; backups are kept on a separate machine and the current retention is 90 days.
  • Every backup is integrity-checked after it is taken, so an empty or corrupt file is not silently counted as a success.

Records and traceability

  • Study creation, switching AI on or off, document upload and deletion, the start and end of an analysis run, accepting or editing a suggestion, undo operations and report generation are recorded.
  • Codebook operations are kept in a separate operation history.
  • Error reports do not include query parameters, that is, data values.

AI and data flow

AI can be switched off per study; when it is off, no new analysis is started for that study. What is sent to the provider when it is on is listed line by line on the Sub-processors page. Because there is no automatic pseudonymization, we recommend replacing names in the transcript before uploading.

What we do not claim

We deliberately avoid some statements that are common on trust pages:

  • We hold no independent certification such as ISO 27001 or SOC 2.
  • We have no published independent penetration test.
  • We make no HIPAA or GDPR compliance claim; the service is provided under Turkish Law No. 6698.
  • We do not commit to how long the AI provider retains your content; the provider's published terms and the account configuration decide that.

Measures on your side

  • Pseudonymize names and direct identifiers in transcripts.
  • Review workspace memberships; use the coder and viewer roles instead of giving everyone researcher rights.
  • For studies restricted by an ethics committee, switch AI off while creating the study.

Reporting a vulnerability

If you find a vulnerability, write to info@youreply.com.tr with the affected address, reproduction steps and, if you have one, an impact assessment. The same contact is published in /.well-known/security.txt.

Code your first interview today

The free plan carries a pilot study from start to finish. No credit card required.