Skip to content
RevXAI
Security & data handling

Built like a B2B platform. Honest about what's certified.

Workspace-isolated, role-based, audit-logged, encrypted at rest, with auditable entitlement and wallet state. We describe what we do, plainly — and name what we have not yet certified.

Compliance & data residency

Built around the regulators your team already answers to.

  • PDPLSaudi Personal Data Protection Law
  • SAMASaudi Arabian Monetary Authority
  • CITCCommunications, Space & Tech Commission
  • ZATCAZakat, Tax & Customs Authority
  • SDAIASaudi Data & AI Authority
  • GDPREU General Data Protection Regulation
  • SOC 2Type II — in progress

Data stored in-region. Saudi sovereign hosting on request.

What's true today

Eight specific practices, audited end-to-end.

Each one is a backend object — not a marketing claim. PRD §13 + §45.

  • Workspace isolation

    Profiles, briefs, sequences, calibration items, contacts, lists, and audit logs are scoped per workspace. Row-level workspace_id constraints enforce no cross-tenant data bleed.

    PRD §13
  • Role-based access control

    Six roles per PRD §13 — owner, admin, operator, viewer, internal_demo, internal_ops_admin. Explicit permissions on profile, brief, sequence, calibration, billing, and member actions. Role changes audited.

    PRD §13
  • Audit log

    Every profile generation, brief, sequence approval, calibration edit, role change, billing change, threshold event, and admin override is recorded with user, timestamp, and payload diff. Available to workspace owners.

    PRD §13, §45
  • Refresh-token rotation

    Auth tokens rotate on every refresh. If a refresh token is reused (a sign of theft), the entire session family is revoked.

    PRD §13
  • Encryption in transit and at rest

    All traffic over TLS 1.2+. Production data encrypted at rest using cloud-provider managed keys. Provider credentials (Instantly, HubSpot, PDL, Coresignal, Lusha, Apollo, Stripe, calendars) stored encrypted.

    PRD §45
  • Workspace export & deletion

    Owners can export profile, brief, sequence, contact, and list data. Deletion is honored within 30 days, with read-only retention only where legally required.

    PRD §31.2
  • Auditable entitlement & wallet state

    Entitlement snapshots, credit wallet balances, profile allowance state, threshold events, and override records are durable backend objects with audit-ready state — not superficial UI logic.

    PRD §8.4
  • Restricted admin access

    Wallet adjustments, override records, and admin impersonation are logged with named operator and reason. Production database access is logged.

    PRD §45
Honesty

What we have not yet certified.

Stating absences plainly is the most powerful trust move on this page.

StandardStatus
SOC 2 Type IINot yet pursued
ISO 27001Not yet pursued
PDPL (Saudi)Aligned in practice; not formally certified
GDPRNot currently in scope
HIPAANot in scope
  • SOC 2 Type IITargeted post-V1; observation period planning underway.
  • ISO 27001Decision paired with SOC 2 timing.
  • PDPL (Saudi)Workspace isolation, audit log, deletion, and secrets encryption honor PDPL principles. Formal compliance review pending.
  • GDPRWe do not target EU markets at this stage. Raise it on the demo call if you need it.
  • HIPAAWe do not handle PHI.

If your procurement requires any of these as a hard gate, we'll tell you that on the demo call rather than waste your team's time.

Specifics

Data handling — answered plainly.

  • What data does RevXAI store about my workspace?

    Profile inputs and outputs, campaign briefs, messaging drafts and sent copies, calibration items, contacts and lists, sequence/launch state, inbox threads for reply-assist (PRD §24.3), user accounts, audit log entries, entitlement snapshots, wallet ledger, threshold events, and Stripe subscription state. Plus standard product analytics events.
  • What does RevXAI NOT store?

    Credit card data — handled by Stripe, never touches our servers. Email contents from outside your sequences. Social-network OAuth tokens beyond what you explicitly connect. No browser fingerprinting beyond standard analytics.
  • Where does data live?

    Production data hosted on {{cloud provider}} in {{region}}. Backups in the same region, encrypted. Logs retained 90 days. The infra team confirms specifics on the security review call.
  • Who at RevXAI can see my workspace data?

    A small number of named engineers and ops staff with audited access (internal_ops_admin role, PRD §13). Production access is logged. Admin impersonation is logged with reason and duration. We do not read your contents for marketing, training, or model improvement without explicit opt-in.
  • Do you train AI models on my data?

    No. We call third-party LLM APIs (the model provider is named in our DPA). We do not fine-tune. Calibration items, profiles, briefs, and sequence drafts are passed at request time only and are not retained by the model provider beyond the API call.
  • Who are your sub-processors?

    LLM API provider (named in DPA), cloud hosting, Stripe (payments), Instantly (email + warmup), PDL · Coresignal · Lusha · Apollo (contact data), HubSpot (CRM, when connected by you), calendar providers (Cal.com / Google / Outlook, when connected). Full list shipped with the DPA.
For your security reviewer

What we'll provide on the demo call.

All shared after a mutual NDA.

  • Architecture diagram

    Data-flow map across the four pillars (intelligence → strategy → execution → visibility).

  • Sub-processor list

    Current named processors with status, region, and DPA references.

  • DPA template

    Mutual NDA available on request before the DPA itself is shared.

  • Pen-test summary

    Most recent pen-test summary, on request and under NDA.

Bring this page to your CFO. We'll bring the rest.

If trust is the blocker, the call is the unblocker.