Built like a B2B platform. Honest about what's certified.
Workspace-isolated, role-based, audit-logged, with encrypted connector credentials and a credit ledger you can audit. We describe what we do, plainly — and name what we have not yet certified.
Eight practices, described as they work today.
Each item describes how the product behaves now — not a roadmap promise.
Workspace isolation
Profiles, briefs, sequences, calibration items, contacts and lists carry a workspace id. Every API request is authenticated and checked against workspace membership before anything is read or written.
Role-based access control
Four customer roles — owner, admin, operator and viewer. Launching, editing, billing and member management are gated by role, and role changes are audit-logged.
Audit log
Sensitive actions — role and member changes, billing changes, credit adjustments, admin overrides and support impersonation — are written to an audit log with the user and time. Records are available to your security reviewer on request.
Accounts and sessions
Email verification is required before first sign-in. Passwords are hashed with bcrypt, and signed session tokens expire after seven days.
Encryption in transit and at rest
All traffic is served over HTTPS. OAuth tokens and mailbox credentials for the accounts you connect (Gmail, Microsoft 365, HubSpot, calendars, SMTP) are stored encrypted with AES-256-GCM.
Data requests
Campaign briefs and the credit ledger export in-product. For a copy of your workspace data or its deletion, contact us and we handle it with you directly — self-serve tooling for both is not built yet.
Auditable entitlement & wallet state
Plan entitlements, wallet balances, profile allowance and every credit movement are recorded server-side in a ledger — not computed in the browser.
Restricted admin access
Credit adjustments, overrides and support impersonation are limited to platform administrators and logged with the operator and reason. Impersonation sessions expire after 30 minutes.
What we have not yet certified.
Stating absences plainly is the most powerful trust move on this page.
| Standard | Status | Note |
|---|---|---|
| SOC 2 Type II | Not yet pursued | No audit is scheduled yet. We will publish a date here when one is. |
| ISO 27001 | Not yet pursued | Decision paired with SOC 2 timing. |
| PDPL (Saudi) | Aligned in practice; not formally certified | We follow its principles — purpose-limited processing, workspace isolation, access control — but have not had a formal compliance review. |
| GDPR | Not currently in scope | We do not target EU markets at this stage. Raise it on the demo call if you need it. |
| HIPAA | Not in scope | We do not handle PHI. |
- SOC 2 Type II — No audit is scheduled yet. We will publish a date here when one is.
- ISO 27001 — Decision paired with SOC 2 timing.
- PDPL (Saudi) — We follow its principles — purpose-limited processing, workspace isolation, access control — but have not had a formal compliance review.
- GDPR — We do not target EU markets at this stage. Raise it on the demo call if you need it.
- HIPAA — We do not handle PHI.
If your procurement requires any of these as a hard gate, we'll tell you that on the demo call rather than waste your team's time.
Data handling — answered plainly.
What data does RevXAI store about my workspace?
Profile inputs and outputs, campaign briefs, message drafts and sent copies, calibration items, contacts and lists, sequence and launch state, reply threads from connected channels, user accounts, audit log entries, plan and wallet ledger, and Stripe subscription state — plus standard product analytics events.What does RevXAI NOT store?
Card data — Stripe handles payments and card numbers never touch our servers. Credentials for accounts you have not connected. No browser fingerprinting beyond standard analytics.Where does data live?
Production runs on Railway's managed cloud in the United States (US West), with the database in the same environment. In-region GCC hosting is not available yet. We confirm the details on a security review call.Who at RevXAI can see my workspace data?
A small number of named platform administrators. Support access to a workspace goes through time-limited impersonation that is logged with a reason. We do not read your content for marketing or model training.Do you train AI models on my data?
No. We call third-party language-model APIs at request time to generate output, and we do not train or fine-tune any model on your data.Who are your sub-processors?
Railway (hosting), language-model API providers, Stripe (payments), Sentry (error monitoring), Microsoft 365 (our transactional email), a web-reading service, B2B contact-data providers, the email warm-up and mailbox provider behind RevX WarmUp, and — only when you connect them — Google, Microsoft, HubSpot, LinkedIn and WhatsApp. The named list comes with the DPA.
What we'll provide on the demo call.
All shared after a mutual NDA.
Architecture diagram
Data-flow map from research to sending and replies, including every connected account.
Sub-processor list
Current named processors with status, region, and DPA references.
DPA template
Mutual NDA available on request before the DPA itself is shared.
Security review summary
Findings and fixes from our most recent internal security review, under NDA. No third-party pen test yet.
Bring this page to your CFO. We'll bring the rest.
If trust is the blocker, the call is the unblocker.
