Security & Data Isolation

How AWG Reachify keeps every business account separate, every connection encrypted and every profile under your control.

How we protect your data

Six controls that sit underneath every card, bio link and analytics report on the platform.

Multi-Tenant Data Isolation

Every record in AWG Reachify is bound to the account that created it. Row-level security is enforced at the database layer, so one customer's cards, links, contacts and analytics can never be read or modified by another — even if a request is crafted by hand.

Managed Authentication

We never store or handle your password. Sign-in is handled by our platform's managed identity layer using short-lived tokens, with sessions verified on every request.

Encryption In Transit & At Rest

All traffic is served exclusively over HTTPS with TLS, including cards published on your own custom domain. Stored data and uploaded files are encrypted at rest by our infrastructure providers.

You Control What Is Public

A card or bio link is only reachable publicly once you press Publish. Unpublished drafts stay private to your account, and you can unpublish at any time to take a profile offline instantly.

Least-Privilege Team Access

Team members only see the cards they own or are assigned. Roles such as viewer restrict editing, and removing a member revokes their access immediately.

Hardened Infrastructure

The platform runs on managed cloud infrastructure with automated patching, network isolation and continuous availability monitoring — no unmaintained servers in the path of your data.

Our operating practices

Payments never touch our servers

All subscription payments are processed by Stripe, a PCI DSS Level 1 certified provider. Card numbers are entered directly into Stripe's hosted checkout — we only ever receive a payment reference and plan status.

Minimal data collection

We only collect what is needed to run your account and your cards. Analytics are recorded as aggregate interaction events (views, scans, taps) rather than personal profiles of your visitors.

Backups and durability

Your data is stored on redundant, automatically backed-up managed storage, so an isolated hardware failure does not put your cards or analytics at risk.

Secure file handling

Photos, logos and cover images are uploaded to managed object storage over encrypted connections and served from a hardened content delivery layer.

Change discipline

Platform updates are deployed through a controlled release process with the ability to roll back, so security fixes ship quickly without destabilising live cards.

Vendor review

We keep our sub-processor list short and rely on established providers with recognised security certifications and data-processing terms.

Your rights and your exit

You can export your analytics as CSV, delete any card or bio link at any time, and request full erasure of your account data. We act as processor for the contact details you publish and comply with UK & EU GDPR.

Reporting a vulnerability

If you believe you have found a security issue, please tell us before disclosing it publicly. We investigate every report, keep you updated, and will never pursue action against good-faith research.

Contact our team