Revent Lab

Security

Straight answers, before you connect a thing.

Every claim here was checked against the code that runs the platform, not written from memory. Where something is still on the way, it says so.

  • AES-256-GCM at rest
  • Isolated per workspace
  • Least-privilege access
  • We train no models on your data
  • Enforced CSP + HSTS
  • Card data never touches us

Verified against the running platform on 16 September 2026.

How it is built

Six things that protect your data.

The lifecycle

What happens to your data, start to finish.

  1. Connect

    You grant one agent one purpose-scoped permission. An admin has to approve it, and the handshake is protected against forgery.

  2. Ingest

    Only the data inside that permission is read, on your behalf, and only when an agent needs it.

  3. Encrypt

    It is sealed with your workspace's own key before it is stored. Tokens are encrypted the same way.

  4. Isolate

    Every later read is scoped to your workspace, and for the private brain to you personally, from your signed session.

  5. Process

    An agent sends only the content a task needs to the model providers listed below. Nothing is used to train them.

  6. Erase

    You can delete the workspace yourself. We destroy the key, revoke the connections, and the encrypted data becomes unreadable.

The questions you should ask

Answered plainly, including where the answer is no.

Where does my data physically live?
Your workspace data sits in managed Postgres, and the AI processing happens with the providers in the table below. The authoritative statement of where each of those sits, and the safeguards for any transfer between them, is in our privacy policy — we keep residency in one place rather than restating it here and letting the two drift apart.
Is my data encrypted in transit and at rest?
Yes, both. In transit it is HTTPS only, with HSTS telling your browser never to try plain HTTP. At rest, sensitive values are sealed with authenticated AES-256-GCM under a key belonging to your workspace alone, and database connections themselves require TLS.
How is my workspace isolated from other customers?
The boundary is re-derived from your signed server session on every request and enforced in the SQL, not applied as a filter after the fact and not trusted from the client. Each workspace also has its own encryption key, so even at the storage layer one customer's data is not readable with another's key. Today that isolation is enforced in the application layer; a database-level backstop is on our roadmap as defence in depth.
What permissions do you actually ask for?
Only what a given agent needs, on its own grant. On Google, agents that only read are only ever given read access. Two — Procurement and Sales — carry a send permission, because sending RFQs and follow-ups is their job, and they ask for it separately and explicitly. What goes out on it was either approved by a person, message by message, or sent under an auto-send policy that is off until you switch it on and reaches only the suppliers or contacts on your list at the moment a message is queued; switching it off stops any further automatic sends, though a message already in its short sending window may still go out. The one exception is a pair of fixed, templated replies Procurement can send to a supplier already on file who emails you — asking for the details a quote is missing when a message does not read as a usable quote, or noting that a quote from them is already on record for that request, so the new email was not taken as another quote. You can see the exact permission on the consent screen before you grant it, and revoke it from your Google account at any time.
Is my data used to train AI models?
We train no model of our own on your data, and one customer's data never informs another's results. For the providers we send content to, we will only claim what their terms actually say: Anthropic, who provide the reasoning, are contractually prohibited from training on the data they process for us and delete it within 30 days by default; Voyage, who generate the embeddings behind search, are configured so your content is not used for training and is not retained after processing. Our speech-to-text and Arabic-language providers are covered by their standard commercial terms, which we are in the middle of confirming in writing — until that is done we are not going to make the same promise on their behalf.
What happens when I disconnect — can I really delete everything?
Yes, and you can do it yourself from your workspace settings without asking us. Deleting a workspace destroys that workspace's encryption key — so the stored data becomes cryptographically unrecoverable — and removes the records. We also call Google's revoke endpoint for your tokens, though that call is made after the deletion and is not retried if Google is unreachable, so the certain way to end access is to remove it from your own Google account too. Encrypted backups age out on their retention schedule afterwards, which we would rather state plainly than imply is instant.
How do you defend against prompt injection and ordinary app-sec risk?
Untrusted content is fenced and labelled as data before a model sees it, so a message someone sends you cannot issue commands to your agents. On the web side, an enforced per-request Content-Security-Policy is the main control. Every pull request is scanned for vulnerable dependencies and for leaked secrets, with a full-history sweep every week, and the scanner binaries are pinned and checksum-verified so a compromised release cannot be swapped in.
Are you SOC 2 or ISO 27001 certified?
Not yet, and we would rather say so than imply otherwise. We are a security-by-design build that is pre-certification: the controls above are real and in the code today, but they have not been audited by an independent third party. Google app verification and the associated security assessment are in progress. If certification is a hard requirement for you, tell us — it helps us sequence it.

Sub-processors

Everyone who touches your data.

The complete list, including the optional integrations that only apply if you connect them. If a service is not here, it does not receive your data.

ServiceWhyWhat it receives
Anthropic (Claude)The reasoning behind your agentsThe specific content a task needs. Contractually never used for training, deleted within 30 days.
Voyage AIEmbeddings that make your content searchableText passages, to turn into search vectors. Not used for training, not retained.
GroqSpeech-to-textAudio you submit for transcription.
Cohere · Hugging FaceArabic-language reasoningThe prompt content for an Arabic task, routed to a hosted Arabic model.
Google APIsThe source of the data you connectScope-limited access to what you grant. Tokens and content are stored encrypted.
Google AnalyticsMeasuring visits to our public websitePage views, browser and device details, and approximate location from visitors to our public pages. Switched off inside the product, so no workspace data reaches it.
Neon (Postgres)The managed databaseAll application data. Sensitive fields are stored as ciphertext.
StripeBillingYour card details, handled entirely by Stripe, plus subscription metadata.
ResendSending transactional emailThe recipient address and the contents of that email.
Cloudflare R2Storing media you publish or uploadThe image and media files themselves.
SentryError monitoringServer-side error context. Personal-data capture is switched off, and there is no browser tracking or session recording.
GitHubTurning your feedback into fixesFeedback you submit in the product, written into our private issue tracker so an engineer can act on it.
DigitalOceanRunning the applicationTechnical connection data such as IP addresses, not your business content.
Slack · Microsoft Teams(optional)Chat, if you connect itMessages with the bot and the channels it is in. Tokens stored encrypted.
Fireflies(optional)Meeting notes, if you connect itThe transcripts you choose to bring in. Your API key is stored encrypted and never shown again.
Google Ads(optional)Ad accounts, if you connect themAccess to the ad account you connect. Nothing is spent without your approval.
LinkedIn(optional)Publishing to LinkedIn, if you connect itThe posts and media you approve for publication.
Meta (Facebook · Instagram)(optional)Publishing to Facebook and Instagram, if you connect themThe posts and media you approve for publication.
X(optional)Publishing to X, if you connect itThe posts and media you approve for publication.
WhatsApp(optional)WhatsApp messaging, if you connect itThe messages sent and received on the number you connect.

Where we are

What is done, and what we are still building.

In the code today

  • Envelope encryption with a key per workspace
  • Workspace and per-person isolation from the signed session
  • Purpose-separated, least-privilege connections
  • Enforced per-request Content-Security-Policy, HSTS and hardened headers
  • Self-serve deletion with cryptographic erasure and token revocation
  • Dependency and secret scanning on every change, plus a weekly sweep
  • Signature-verified webhooks and Stripe-hosted payments
  • Server-side-only error monitoring with personal-data capture off

What we are building next

  • Independent certification. We do not hold SOC 2 or ISO 27001 today. The controls are real and in the code; they have not been third-party audited, and we will not imply otherwise.
  • Google app verification and the associated security assessment, in progress.
  • Continued hardening — key management, database-level defence in depth, and automated retention tooling.

The brief is this page on paper — made to forward, or to attach to a security review. If you are evaluating us seriously and want more, we also keep a detailed engineering ledger of exactly what is shipped, what is configuration and what is still open, with the evidence behind each line; ask and we will share that one under NDA.

Download the security brief (PDF)

Found something, or need something?

Security questions, a review request, or a vulnerability report — write to us and a person will answer.

security@revent.store