Security and privacy
CHAMPREP uses layered safeguards across identity, access, application delivery, infrastructure, and customer-controlled data. This page describes controls that we can verify today. It deliberately does not claim a certification, audit, test, response target, or security control that has not been completed and approved for public release.
For a concise overview suitable for security and procurement teams, visit the CHAMPREP Security & Trust page.
Security at a glance
Section titled “Security at a glance”- Public CHAMPREP service connections use HTTPS and modern TLS.
- Managed object and file storage uses private origin access and is configured with server-side encryption.
- Accounts support email verification, two-factor authentication, recovery codes, passkeys, session review, and sign-in alerts.
- Organization access follows the active profile, role, entitlement, and service-specific permission.
- Continuous-integration pipelines include automated static security analysis and secret detection.
- Centralized operational logs, health metrics, and alarms support service investigation and response.
- Core production application infrastructure is deployed in United States AWS regions.
Encryption and storage protection
Section titled “Encryption and storage protection”Data in transit
Section titled “Data in transit”Public connections to CHAMPREP services use HTTPS. The platform’s public load balancers and content-delivery configuration redirect or require encrypted connections and use modern TLS policies.
Data at rest
Section titled “Data at rest”Managed object and file storage is configured with server-side encryption and private access controls. Static application origins, user files, and similar object-storage workloads are not exposed as publicly writable storage.
This verified statement is intentionally scoped. CHAMPREP does not currently describe encryption at rest as a universal fleet-wide control on this page. The remaining database, cache, backup, and service-specific paths must each complete the same assurance review before that broader statement is made.
Identity and account protection
Section titled “Identity and account protection”- Email verification confirms a new account before it becomes fully active.
- Two-factor authentication (2FA) supports time-based one-time passwords from a standard authenticator application.
- Recovery codes provide single-use recovery when an authenticator is not available.
- Passkeys support device-backed authentication on compatible browsers and devices.
- Session controls let users review active sessions and sign out devices or browsers they do not recognize.
- Account activity and alerts make security-relevant account events visible to the user.
Manage these controls from the Security, Active Sessions, and Account Activity areas of the personal dashboard.
Authorization and organization boundaries
Section titled “Authorization and organization boundaries”Access is evaluated in the context of the active profile. Changing profiles changes the service, role, organization, and entitlement context used by the platform.
- Plan entitlements determine which services and features are available.
- Organization roles and member-level permissions limit administrative and service actions.
- Enterprise administrators can manage member access, service availability, verified domains, and supported SSO or SCIM capabilities.
- Developer access uses scoped, revocable API credentials rather than account passwords.
- Service identities and runtime roles are granted access to the resources they require instead of using one shared platform credential.
Secure development and vulnerability scanning
Section titled “Secure development and vulnerability scanning”CHAMPREP continuous-integration pipelines run automated static security analysis with security and OWASP-oriented rules. Pipelines also run secret detection to identify credentials or sensitive values that should not enter source control. Findings are surfaced to engineering for review and remediation.
These are the verified scan types represented publicly today. Dependency, container, infrastructure-as-code, dynamic application, and software-bill-of- materials coverage is being handled as a separate assurance expansion and is not implied by this statement.
Monitoring and service resilience
Section titled “Monitoring and service resilience”The platform uses centralized application and infrastructure logs, service health metrics, and alarms for operational conditions such as errors, latency, resource pressure, and unhealthy service targets. Production infrastructure uses availability-zone-aware networking and service placement where configured.
Monitoring data is access controlled. Public documentation does not disclose internal alarm thresholds, account identifiers, network topology, or other details that would make the platform easier to target.
Data location
Section titled “Data location”Core production application infrastructure is deployed in United States AWS regions. CHAMPREP does not use the word “onshore” as an absolute for every data flow: global content delivery, network protection, and approved service providers may process routing or service metadata under their applicable terms.
Customers with specific residency requirements should contact CHAMPREP so the exact services, data classes, and provider paths in scope can be reviewed.
AI choice and control
Section titled “AI choice and control”Using CHAMPREP AI is optional. AI operates within the permissions of the active profile and does not create broader service access for itself.
- Users can enable or disable AI access to connected services.
- Action-taking or agentic capabilities are disabled by default until a user explicitly enables them.
- Service and plan permissions continue to apply when AI assistance is used.
- Higher-impact actions can require user approval.
CHAMPREP is continuing to strengthen platform-wide consent defaults and organization-level AI policy controls. We do not describe every AI feature as opt-in by default until that work has been verified across the full platform.
Your privacy and data controls
Section titled “Your privacy and data controls”- Export your data from the personal dashboard when the export option is available for the relevant account data.
- Review sharing and retention in the service that owns a file, recording, transcript, room, or other item.
- Close your account through the dashboard’s close-account flow after reviewing the on-screen consequences.
- Read the Privacy Policy and Terms of Service for the governing privacy and service terms.
Report a vulnerability
Section titled “Report a vulnerability”Submit a report through champrep.com/contact-us and begin the subject with [Security] Vulnerability report.
Include:
- The affected CHAMPREP service or URL.
- A clear description of what you observed.
- The smallest safe set of steps needed to reproduce it.
- The potential impact, if known.
- Your preferred contact details for follow-up.
Do not include passwords, authentication tokens, payment data, customer content, or more personal data than is necessary to explain the issue. Do not disrupt service, access another person’s data, or retain data discovered during testing. A machine-readable disclosure pointer is also available at champrep.com/.well-known/security.txt.
Reports are triaged by severity and routed to the appropriate engineering owner. CHAMPREP does not publish a response-time promise on this page until a formal incident and vulnerability-response target has been approved and tested.
Enterprise security review
Section titled “Enterprise security review”Enterprise security, risk, and procurement teams may use the contact form to request a focused review. CHAMPREP will only provide a penetration-test summary, audit report, certification, or similar assurance artifact when that artifact exists, is current, and has been approved for release.