Built like a B2B platform. Honest about what's certified.
Workspace-isolated, role-based, audit-logged, encrypted at rest, with auditable entitlement and wallet state. We describe what we do, plainly — and name what we have not yet certified.
Built around the regulators your team already answers to.
- PDPLSaudi Personal Data Protection Law
- SAMASaudi Arabian Monetary Authority
- CITCCommunications, Space & Tech Commission
- ZATCAZakat, Tax & Customs Authority
- SDAIASaudi Data & AI Authority
- GDPREU General Data Protection Regulation
- SOC 2Type II — in progress
Data stored in-region. Saudi sovereign hosting on request.
Eight specific practices, audited end-to-end.
Each one is a backend object — not a marketing claim. PRD §13 + §45.
Workspace isolation
Profiles, briefs, sequences, calibration items, contacts, lists, and audit logs are scoped per workspace. Row-level workspace_id constraints enforce no cross-tenant data bleed.
PRD §13Role-based access control
Six roles per PRD §13 — owner, admin, operator, viewer, internal_demo, internal_ops_admin. Explicit permissions on profile, brief, sequence, calibration, billing, and member actions. Role changes audited.
PRD §13Audit log
Every profile generation, brief, sequence approval, calibration edit, role change, billing change, threshold event, and admin override is recorded with user, timestamp, and payload diff. Available to workspace owners.
PRD §13, §45Refresh-token rotation
Auth tokens rotate on every refresh. If a refresh token is reused (a sign of theft), the entire session family is revoked.
PRD §13Encryption in transit and at rest
All traffic over TLS 1.2+. Production data encrypted at rest using cloud-provider managed keys. Provider credentials (Instantly, HubSpot, PDL, Coresignal, Lusha, Apollo, Stripe, calendars) stored encrypted.
PRD §45Workspace export & deletion
Owners can export profile, brief, sequence, contact, and list data. Deletion is honored within 30 days, with read-only retention only where legally required.
PRD §31.2Auditable entitlement & wallet state
Entitlement snapshots, credit wallet balances, profile allowance state, threshold events, and override records are durable backend objects with audit-ready state — not superficial UI logic.
PRD §8.4Restricted admin access
Wallet adjustments, override records, and admin impersonation are logged with named operator and reason. Production database access is logged.
PRD §45
What we have not yet certified.
Stating absences plainly is the most powerful trust move on this page.
| Standard | Status | Note |
|---|---|---|
| SOC 2 Type II | Not yet pursued | Targeted post-V1; observation period planning underway. |
| ISO 27001 | Not yet pursued | Decision paired with SOC 2 timing. |
| PDPL (Saudi) | Aligned in practice; not formally certified | Workspace isolation, audit log, deletion, and secrets encryption honor PDPL principles. Formal compliance review pending. |
| GDPR | Not currently in scope | We do not target EU markets at this stage. Raise it on the demo call if you need it. |
| HIPAA | Not in scope | We do not handle PHI. |
- SOC 2 Type II — Targeted post-V1; observation period planning underway.
- ISO 27001 — Decision paired with SOC 2 timing.
- PDPL (Saudi) — Workspace isolation, audit log, deletion, and secrets encryption honor PDPL principles. Formal compliance review pending.
- GDPR — We do not target EU markets at this stage. Raise it on the demo call if you need it.
- HIPAA — We do not handle PHI.
If your procurement requires any of these as a hard gate, we'll tell you that on the demo call rather than waste your team's time.
Data handling — answered plainly.
What data does RevXAI store about my workspace?
Profile inputs and outputs, campaign briefs, messaging drafts and sent copies, calibration items, contacts and lists, sequence/launch state, inbox threads for reply-assist (PRD §24.3), user accounts, audit log entries, entitlement snapshots, wallet ledger, threshold events, and Stripe subscription state. Plus standard product analytics events.What does RevXAI NOT store?
Credit card data — handled by Stripe, never touches our servers. Email contents from outside your sequences. Social-network OAuth tokens beyond what you explicitly connect. No browser fingerprinting beyond standard analytics.Where does data live?
Production data hosted on {{cloud provider}} in {{region}}. Backups in the same region, encrypted. Logs retained 90 days. The infra team confirms specifics on the security review call.Who at RevXAI can see my workspace data?
A small number of named engineers and ops staff with audited access (internal_ops_admin role, PRD §13). Production access is logged. Admin impersonation is logged with reason and duration. We do not read your contents for marketing, training, or model improvement without explicit opt-in.Do you train AI models on my data?
No. We call third-party LLM APIs (the model provider is named in our DPA). We do not fine-tune. Calibration items, profiles, briefs, and sequence drafts are passed at request time only and are not retained by the model provider beyond the API call.Who are your sub-processors?
LLM API provider (named in DPA), cloud hosting, Stripe (payments), Instantly (email + warmup), PDL · Coresignal · Lusha · Apollo (contact data), HubSpot (CRM, when connected by you), calendar providers (Cal.com / Google / Outlook, when connected). Full list shipped with the DPA.
What we'll provide on the demo call.
All shared after a mutual NDA.
Architecture diagram
Data-flow map across the four pillars (intelligence → strategy → execution → visibility).
Sub-processor list
Current named processors with status, region, and DPA references.
DPA template
Mutual NDA available on request before the DPA itself is shared.
Pen-test summary
Most recent pen-test summary, on request and under NDA.
Bring this page to your CFO. We'll bring the rest.
If trust is the blocker, the call is the unblocker.
