Security
Measures we have implemented, described without embellishment.
This page lists controls that exist in the product today. Anything not listed here should be assumed absent until we confirm otherwise in writing.
Platform controls
- Tenant isolation enforced by database row-level security policies.
- Role separation between organization administrators and analysts, with server-side authorization on privileged actions.
- Full phone numbers protected in storage and surfaced in masked form for review.
- Delivery credentials encrypted before storage and never returned in full to the interface.
- Outbound delivery restricted to HTTPS, with destination checks that refuse internal or private network targets.
- One-time code verification with attempt limits, resend cooldown, and server-side expiry.
- Append-only revocation and delivery records, so history cannot be quietly rewritten.
- Auditable administrative events, including cross-organization access by revoq staff during support.
- Sanitized and truncated destination responses, so credentials do not land in evidence.
Reporting a vulnerability
If you believe you have found a security issue, tell us before telling anyone else. Send the details through the contact form, noting that it is a security report, and include enough detail to reproduce the issue.
Please do not access, modify, or exfiltrate data that is not yours, do not run tests that degrade the service for others, and give us a reasonable opportunity to respond before any public disclosure. We will acknowledge reports and keep the reporter informed while we investigate.
Security questions from procurement
Detailed answers about hosting, subprocessors, retention, access management, and incident handling are provided per organization rather than published as blanket statements. Ask in a readiness review and you will get specific answers about the current implementation.