Security and compliance

Enforced in code, not in a policy.

Outbound touches other people's inboxes and phone lines. That makes compliance an engineering problem, so we built it as one. Here is exactly what runs and what does not exist yet.

Before every action

Six checks run before anything sends.

Not a nightly job, not a review queue. A function that runs before every single email and every single call, and records its verdict either way.

Suppression check

Global and account level, inside the same transaction as the send

Voice consent

Published business lines by default. Mobile numbers require recorded consent

Calling hours

Computed from the prospect's own timezone, not yours

Attempt caps

Four call attempts maximum, spread across different parts of the day

AI disclosure

Stated in the opening line of every call, every time

Opt out

Honored immediately, permanently, and across every channel

On AI voice specifically. The FCC has held that calls using AI generated voices fall under the same consent rules as prerecorded robocalls. Revio therefore targets published business lines by default. Calling a mobile number requires that you record prior express written consent for that contact, with a source and a timestamp, and the system will not place the call without it. We build no feature whose purpose is evading spam filters, caller identification, or consent requirements.

Platform controls

How your data is held.

Tenant isolation

Every table carries a tenant id and a Postgres row level security policy. Isolation is enforced by the database, not by application code remembering a WHERE clause. A query without the right session context returns nothing at all.

Encryption

TLS 1.2 or higher in transit. AES 256 at rest. Mailbox credentials and OAuth tokens are stored with envelope encryption and never written to application logs.

Access control

Four roles: owner, admin, member, viewer. Enforced at the API boundary and again at the row level. Enterprise accounts add SSO and SCIM provisioning.

Audit logging

Every send, call, configuration change, and export writes an immutable audit record with actor, target, before, after, and timestamp. Records cannot be updated or deleted, including by us.

Recordings and retention

Call recordings and transcripts are encrypted at rest with a retention window you set. Delete a prospect and the associated media goes with it.

Webhooks and rate limits

Inbound webhooks are HMAC verified with a replay window. Per tenant and per endpoint rate limits are applied at the edge.

Current status

What exists today, and what does not.

Security pages usually list aspirations as if they were facts. This one separates them, because you are going to ask in the security review anyway.

Row level tenant isolationIn place
Encryption in transit and at restIn place
Immutable audit logIn place
Data export and deletionIn place
SSO and SCIMEnterprise, on request
SOC 2 Type IINot yet. Planned once we are past our first cohort
Penetration testScheduled before general availability

Security review before the demo?

That is a reasonable order to do it in. Send us your questionnaire and we will answer it directly rather than pointing you at a trust badge.