Skip to content
RevXAI
Security & data handling

Built like a B2B platform. Honest about what's certified.

Workspace-isolated, role-based, audit-logged, with encrypted connector credentials and a credit ledger you can audit. We describe what we do, plainly — and name what we have not yet certified.

What's true today

Eight practices, described as they work today.

Each item describes how the product behaves now — not a roadmap promise.

  • Workspace isolation

    Profiles, briefs, sequences, calibration items, contacts and lists carry a workspace id. Every API request is authenticated and checked against workspace membership before anything is read or written.

  • Role-based access control

    Four customer roles — owner, admin, operator and viewer. Launching, editing, billing and member management are gated by role, and role changes are audit-logged.

  • Audit log

    Sensitive actions — role and member changes, billing changes, credit adjustments, admin overrides and support impersonation — are written to an audit log with the user and time. Records are available to your security reviewer on request.

  • Accounts and sessions

    Email verification is required before first sign-in. Passwords are hashed with bcrypt, and signed session tokens expire after seven days.

  • Encryption in transit and at rest

    All traffic is served over HTTPS. OAuth tokens and mailbox credentials for the accounts you connect (Gmail, Microsoft 365, HubSpot, calendars, SMTP) are stored encrypted with AES-256-GCM.

  • Data requests

    Campaign briefs and the credit ledger export in-product. For a copy of your workspace data or its deletion, contact us and we handle it with you directly — self-serve tooling for both is not built yet.

  • Auditable entitlement & wallet state

    Plan entitlements, wallet balances, profile allowance and every credit movement are recorded server-side in a ledger — not computed in the browser.

  • Restricted admin access

    Credit adjustments, overrides and support impersonation are limited to platform administrators and logged with the operator and reason. Impersonation sessions expire after 30 minutes.

Honesty

What we have not yet certified.

Stating absences plainly is the most powerful trust move on this page.

StandardStatus
SOC 2 Type IINot yet pursued
ISO 27001Not yet pursued
PDPL (Saudi)Aligned in practice; not formally certified
GDPRNot currently in scope
HIPAANot in scope
  • SOC 2 Type IINo audit is scheduled yet. We will publish a date here when one is.
  • ISO 27001Decision paired with SOC 2 timing.
  • PDPL (Saudi)We follow its principles — purpose-limited processing, workspace isolation, access control — but have not had a formal compliance review.
  • GDPRWe do not target EU markets at this stage. Raise it on the demo call if you need it.
  • HIPAAWe do not handle PHI.

If your procurement requires any of these as a hard gate, we'll tell you that on the demo call rather than waste your team's time.

Specifics

Data handling — answered plainly.

  • What data does RevXAI store about my workspace?

    Profile inputs and outputs, campaign briefs, message drafts and sent copies, calibration items, contacts and lists, sequence and launch state, reply threads from connected channels, user accounts, audit log entries, plan and wallet ledger, and Stripe subscription state — plus standard product analytics events.
  • What does RevXAI NOT store?

    Card data — Stripe handles payments and card numbers never touch our servers. Credentials for accounts you have not connected. No browser fingerprinting beyond standard analytics.
  • Where does data live?

    Production runs on Railway's managed cloud in the United States (US West), with the database in the same environment. In-region GCC hosting is not available yet. We confirm the details on a security review call.
  • Who at RevXAI can see my workspace data?

    A small number of named platform administrators. Support access to a workspace goes through time-limited impersonation that is logged with a reason. We do not read your content for marketing or model training.
  • Do you train AI models on my data?

    No. We call third-party language-model APIs at request time to generate output, and we do not train or fine-tune any model on your data.
  • Who are your sub-processors?

    Railway (hosting), language-model API providers, Stripe (payments), Sentry (error monitoring), Microsoft 365 (our transactional email), a web-reading service, B2B contact-data providers, the email warm-up and mailbox provider behind RevX WarmUp, and — only when you connect them — Google, Microsoft, HubSpot, LinkedIn and WhatsApp. The named list comes with the DPA.
For your security reviewer

What we'll provide on the demo call.

All shared after a mutual NDA.

  • Architecture diagram

    Data-flow map from research to sending and replies, including every connected account.

  • Sub-processor list

    Current named processors with status, region, and DPA references.

  • DPA template

    Mutual NDA available on request before the DPA itself is shared.

  • Security review summary

    Findings and fixes from our most recent internal security review, under NDA. No third-party pen test yet.

Bring this page to your CFO. We'll bring the rest.

If trust is the blocker, the call is the unblocker.