Security · Trust Center

Governed from day one. Audited from day one

SOC 2 Type II, ISO 27001:2022, ISO 42001:2023 for responsible AI. Every agent action logged. Every action reversible.

SOC 2 Type II badge
SOC 2 Type II
Audited annually
ISO 27001:2022 badge
ISO 27001:2022
Information security
ISO 42001:2023 badge
ISO 42001:2023
Responsible AI governance
GDPR · CCPA badge
GDPR · CCPA
Privacy by design
The security stack

Five layers. One audit trail

Encryption, access control, isolation, monitoring, resilience. Built for the enterprise buyer's procurement review.

Encryption
  • AES-256 at rest with rotated symmetric keys
  • TLS 1.3 in transit, SHA-2 cipher suites
  • Key management via Google Cloud KMS
Authentication & Access
  • OAuth and key-based with least-privilege scopes
  • JWT API tokens, SSO/SAML, SCIM
  • 2FA mandatory for admin actions
  • Role-based access control with custom roles
PII & Data Isolation
  • Per-tenant logical isolation
  • Customer-controlled PII masking
  • Field-level redaction per record
  • Sub-processor list disclosed
Audit & Monitoring
  • Immutable audit ledger per action
  • Continuous risk assessment
  • PBKDF2 password hashing
  • Manual + automated pre-deploy code review
Resilience
  • Production snapshots across multi-region
  • RPO < 1 hour, RTO < 4 hours
  • Disaster recovery runbooks tested quarterly
  • Status page with incident history
AI Governance · ISO 42001

The credential nobody else has

ISO 42001:2023 is the international standard for AI management systems. RevSure is among the first attribution platforms to certify.

Safe Autonomy

Propose, approve, commit, rollback by construction. Every action reversible in one click.

No prompt logging

Prompts and outputs not retained beyond the active request, by policy and by audit.

Model safety reviews

Quarterly reviews of every deployed model against the ISO 42001 risk register.

Hallucination flags

Output confidence scored and flagged. Low-confidence outputs gated for human review.

Sub-processors

Disclosed. Documented

Every entity that touches customer data, what role they play, and which jurisdiction. Updated on the security page within 24 hours of any change.

Sub-processorRoleRegionCertifications
Google Cloud PlatformInfrastructureUS (us-central-1a)SOC 1/2/3, ISO 27001
Google Gemini / Vertex AILLMUSSOC 2, ISO 27001
HubSpotMarketing & partnershipUS / EUSOC 2, ISO 27001
LinkedInMarketing & partnershipUSISO 27001, ISO 27018
Responsible disclosure

Found something? Tell us

Email security@revsure.ai with the details. We acknowledge within 24 hours, triage within 72, and remediate based on severity. Bug bounty program in preparation.

Ready when your stack is

Procurement-ready. Day one

Implementation included. SOC 2, ISO 27001, ISO 42001 across every tier. Sub-processors disclosed. Audit ledger immutable.