Security & Compliance
Catalogue diligence involves unreleased deal terms, writer identifiers and financial evidence. This page describes the controls TJ Entertainment Solutions FZE operates in Repertoire Review and the commitments we are able to make today.
Tenancy isolation and access control
- Every record is scoped to an organisation. Database row-level security enforces that scoping on every read and write, so one workspace cannot read another's data even if a request is manipulated.
- Role-based permissions (administrator, legal, publishing, finance, read-only, data-room) are stored separately from user profiles and checked server-side, which prevents client-side privilege escalation.
- Write actions such as editing splits, applying amendments or deleting works require a write role; read-only and data-room users cannot change records.
- Privileged database helpers verify both the caller's organisation and their write role before making a change.
Authentication
- Email and password sign-in with verification, plus Google single sign-on.
- Sessions are token-based and refreshed automatically; signing out clears the local session and cached data.
- Accounts are per person, and administrators can review workspace members and roles at any time in Admin.
Encryption and document storage
- Traffic is encrypted in transit with TLS, and data at rest is encrypted by our infrastructure provider.
- Uploaded documents live in a private bucket with no public URLs; downloads are served through short-lived signed links issued only to authorised members.
- File access events are recorded so you can see who opened what.
Audit trail and change history
Material changes — splits, publisher and administrator positions, agreement terms, applied amendments, diligence status, deletions and rights instructions applied through the assistant — are written to an immutable-by-design audit log capturing the actor, the field, the previous value and the new value. This is what lets you evidence a rights position to a buyer months later.
Data rooms
- Data room links are tokenised, scoped to a single transaction and expire automatically.
- Links can be revoked immediately, and creation, expiry and revocation are logged.
- Only works you have marked as included in the sale are exposed in a data room manifest.
Availability and continuity
- The application and database are hosted on managed cloud infrastructure with automated backups.
- You can export repertoire, statements and data room manifests to CSV at any time, so you are never dependent on us to hold a copy.
Compliance posture — stated plainly
We build to widely accepted security practice: least-privilege access, tenant isolation enforced in the database, encryption in transit and at rest, audit logging and dependency scanning. We do not currently claim SOC 2, ISO 27001, HIPAA or PCI certification, and we will not imply an audit we have not completed. If your acquisition or vendor process requires a security questionnaire, a data processing agreement or a named subprocessor list, contact us and we will complete it against the controls actually in place.
Reporting a vulnerability
We welcome good-faith reports. Email security@repertoirereview.app with steps to reproduce and the impact you observed. Please do not test against another customer's workspace, do not exfiltrate data, and give us a reasonable window to remediate before disclosing publicly. We will acknowledge your report and keep you updated on the fix.
Platform Trust Center
Infrastructure-level security evidence for this deployment is published by our hosting platform and maintained independently of this page.
Open the platform Trust Center