Securiity & Trust

Controller: Realify ai Inc (Delaware corporation, File No. 10409872)
Principal Address: 28 Geary St STE 650 494, San Francisco, CA 94108, USA
Development Center (affiliate): Realify AI India Private Limited,
Affiliate Address: Plot No. 629, Sector 82, Sahibzada Ajit Singh Nagar (Mohali), Punjab 140306, India

Contact: legal@realify.ai
Effective Date: June 1st, 2026

Security and Trust — Realify.ai

Realify.ai is built to handle sensitive commercial data including order history, pricing, advertising spend, and buyer information on behalf of brands operating across multiple channels. This page summarises the security controls and practices we apply to protect that data.

For enterprise security questionnaires or to request a penetration test executive summary under NDA, contact legal@realify.ai.

§ 01

Application Infrastructure

All Realify application data including customer data and data accessed through connected platform APIs is stored and processed exclusively on Amazon Web Services (AWS) infrastructure in the United States (us-east-1 and us-west-2). Amazon Information accessed via the SP-API is never transmitted outside the United States.

The realify.ai marketing website is served separately from the application infrastructure. The controls in the table below apply to the application layer where customer data lives.

§ 02

Security Controls

Control AreaStandard Applied
Encryption in transitTLS 1.2+ on all connections; TLS 1.3 where supported. SFTP/SSH-2 for file transfers.
Encryption at restAES-256 for all stored data including databases, file storage, backups, and archives.
Access controlsRBAC on a least-privilege basis. MFA mandatory for all production access. Quarterly access recertification. Access revoked within 24 hours of departure.
Network infrastructureApplication infrastructure on AWS (us-east-1 and us-west-2). VPC isolation, WAF, IDS/IPS, and anti-malware updated monthly. Note: the realify.ai marketing website is served via a separate CDN and has distinct infrastructure from the application layer.
Vulnerability managementAutomated scanning every 30 days. Annual third-party penetration testing. Critical patches within 7 days, high-risk within 30 days.
Audit loggingAll production access logged with user, action, timestamp, and geographic origin. Retained 12 months minimum. Reviewed monthly.
Incident responseFormal incident response plan. Annual tabletop exercises. Reviewed every 6 months and after major system changes.
Sub-processor oversightDocumented pre-onboarding assessment. Annual review for all sub-processors with access to customer personal data.
§ 03

Responsible Disclosure

If you believe you've found a security vulnerability in Realify's systems, report it to legal@realify.ai with the subject 'Security disclosure'. We ask that you give us reasonable time to investigate before any public disclosure. We do not pursue legal action against researchers who report vulnerabilities in good faith.