Legal

Security at Rehearsa

Last updated June 2026

This summary is provided for transparency and isn’t legal advice.

How we protect your data

Your rehearsals can be candid — false starts, weak structures, the answers you’re still working on. We treat that material with care and build security into the product from the ground up rather than bolting it on. The practices below describe how we work today.

Encryption in transit and at rest

All traffic between you and Rehearsa is encrypted in transit using modern TLS. Your data is encrypted at rest in our databases and storage so that, even at the infrastructure layer, your content is not readable as plain text.

Least-privilege access controls

Access to production systems is limited to the people who need it to do their jobs, granted on a least-privilege basis and reviewed regularly. Administrative access requires strong authentication, and sensitive actions are logged.

Isolated practice data

Your practice sessions, feedback, and scores are logically isolated to your account. Other users can’t see your rehearsals, and your private content isn’t used to generate experiences for anyone else.

You own your data

The responses and materials you create are yours. You can export or delete them, and we never sell your data. We process it only to run and improve your own Rehearsa experience.

Continuous monitoring

We monitor our systems continuously for unusual activity, keep our dependencies patched, and maintain backups so we can recover quickly. Our goal is to catch issues early and keep the service both reliable and safe.

Responsible disclosure

If you believe you’ve found a security vulnerability, please tell us at security@rehearsa.ai. We welcome good-faith reports, will acknowledge your message promptly, and ask that you give us a reasonable window to investigate and fix before any public disclosure.