Trust

Security

Last updated September 24, 2026. Your customers' calls, texts, bookings, and payments run through DREXIFY. This page lists exactly how that information is protected today. It describes what is in place now, not plans.

Your data is walled off from every other business

Each business's records are separated by the database itself, not only by our code. Your dashboard reads your data with a key tied to your business alone, and the database refuses to hand that key any other business's records.

Encrypted on the way and at rest

Every connection to drexify.tech and your dashboard runs over HTTPS, and plain-HTTP requests are redirected to it. Your data is stored in Supabase, a managed database, where it is encrypted at rest.

Card numbers never touch our servers

Payments run on Stripe's own checkout and payment pages. That covers your subscription and the invoices your customers pay. We never see or store a full card number.

Sign-in built to resist guessing

Dashboard passwords are stored only as bcrypt hashes, never as readable text. Your signed-in session lives in a secure cookie that page scripts cannot read, and it expires on its own. Repeated failed sign-ins lock the account for a while, so a password cannot simply be guessed.

We check who is knocking

Stripe, our payment provider, and Twilio, our phone and text carrier, sign every message they send us. We check that signature before acting on it, so nobody can fake a payment or a text by sending us a lookalike message.

Backed up every day

On top of the database provider's own safeguards, we take a full copy of the data every day and keep it separately from the live database, so a bad day does not become lost records.

Your data is not for sale

We never sell your data or your customers' data, and we never use it to train anyone's models. When you leave, your records are deleted on the schedule in our Privacy Policy. You can also ask us to delete them sooner, and we will.

Callers know they are being recorded

Calls to your DREXIFY number are recorded so you can see what was said. Every call opens by telling the caller so, in line with California's two-party consent law. Details are in our Terms of Service.

Who else handles your data

A short list of providers run parts of the service: Stripe for payments, Twilio for calls and texts, Supabase for storage, and a few others for voice and email. Each one receives only what its job needs. The full list, with what each one receives, is in section 4 of our Privacy Policy.

Do you have a SOC 2 report?

Not yet. SOC 2 is an independent audit that larger companies often ask their vendors for. When we complete one, it will be listed on this page. Until then, if your business needs a security questionnaire filled out, send it to us and we will answer it in writing.

Report a security concern

Found something that looks wrong, or have a question this page does not answer? Email team@drexify.tech with "Security" in the subject line, or call (909) 323-0776. A real person reads it.

Get started

Let's get your front desk running.

Set up in about a week, by hand, for your business. Flat monthly rate — no metered minutes, no contracts, cancel anytime.

  • Flat monthly rate
  • No contracts
  • Cancel anytime

Prefer to see the leaks first? Get a free Revenue Leak Report