Security at Revioli

Intelligence earns trust.
Protection makes
it possible.

Your customer data deserves deliberate protection. Revioli limits source access, separates workspace records, sanitizes behavioral evidence, and keeps changes accountable to your team.

01 / ACCESSOnly the permissions
the connection needs.
02 / ISOLATIONYour workspace.
Your authorized records.
03 / CONTROLReviewed changes.
Accountable decisions.

Protection throughout the data journey

Follow the data.
See the safeguards.

Each stage has a specific purpose and a corresponding boundary. Explore how information becomes useful without granting the system unlimited access.

A scoped starting point

Understand billing.
Keep billing control.

The Stripe connector uses restricted, read-only access for approved customer and subscription context. Its requests retrieve information; they do not issue charges, refunds, or subscription changes.

Credential values are resolved through server-side secret handling. Configuration stores references rather than exposing the credential in the public interface.

STRIPE CONNECTION
Read approved billing contextAllowed
Charge or refund a customerOutside scope
Change a subscriptionOutside scope
Your team retains the billing relationship.

Controls with a clear purpose

Less access.
More accountability.

Security works through connected controls. Source permissions, storage boundaries, sanitization, and approval checks address different parts of the data path.

01

Restricted source permissions

Read-only Stripe requests limit what the connector can do with a billing relationship. Credentials belong in the supported server-side configuration path.

02

Tenant isolation and private storage

Workspace identity is enforced around records and stored objects. Raw Atlas storage is private and access is restricted.

03

Sanitized behavioral evidence

Sensitive fields are filtered before they become behavioral evidence. Product activity is kept within its approved scope and source lineage.

04

Approval and auditability

Tracking and mapping changes require a recorded decision. Guarded changes keep audit records, and recommendations leave customer action with your team.

Your data and our AI

Learning has
boundaries too.

Connected customer records support Revioli within your workspace. They are not exposed as another customer’s records or used to train third-party public models.

De-identified, aggregated patterns may support internal model development and evaluation under our Privacy Policy. Identifiable shared-model use requires separate written permission.

Review the model-use policy ↗

Ready for a proper security conversation

The questions
your team should ask.

We’ll review your requirements against the actual connection and deployment you plan to use, including any gaps that need to be addressed before data is connected.

Can we review access and data handling before connecting?

Yes. Share your source permissions, access, retention, and deployment requirements with our team. We will confirm the proposed data path and the documentation available for your review before you provide customer data.

Are you SOC 2 or ISO 27001 certified?

We do not currently claim SOC 2 Type II or ISO 27001 certification. We describe the controls we implement and confirm certification status directly during your review.

What should we review about encryption and hosting?

Review transport protection, storage encryption, credential management, region, retention, and the specific hosting arrangement with us. Deployment-specific requirements such as customer-managed keys, VPC hosting, or on-premise operation require a separate scope review; they are not implied by connecting a source.

Can Revioli send messages or change subscriptions on its own?

No. Recovery recommendations remain advisory. Your team reviews the evidence and owns customer contact, refunds, and subscription decisions. The Stripe connector itself is read-only.

How do we request access, deletion, or a security review?

Contact founders@revioli.com. We review requests under the Privacy Policy and applicable agreements. Please send a description of the request rather than credentials or customer records.

Trust starts with a clear conversation

Bring your requirements.
We’ll work through the details.

Source access, isolation, model use, and data lifecycle should be understandable before you connect.