Last updated: August 25, 2026
We take the security of your business and customer data seriously. This page summarizes the main safeguards built into Repeat Grow.
Inbound WhatsApp webhook requests are verified using HMAC-SHA256 signature checks before being processed, so unsigned or spoofed requests are rejected.
Repeat Grow is built on the official WhatsApp Business API and hosted on Supabase infrastructure, with baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options, Content-Security-Policy, and a restrictive Permissions-Policy) applied to every response.
If you believe you've found a security vulnerability in Repeat Grow, please report it privately to support.repeatgrow@gmail.com rather than disclosing it publicly. We'll acknowledge your report and work with you to understand and address the issue.