Trust center
What revoq does with data, stated no further than we can support.
This page describes safeguards that are implemented in the product today. It deliberately makes no certification, audit, or regulatory-compliance claims.
Data minimization
What revoq collects, and what it avoids
- From consumers
- A US phone number, the scope they selected, and the technical details of the request. No name, address, or account number is required to submit a request.
- Phone numbers
- Displayed and reported in masked form. The full value is protected in storage and is not exposed to ordinary review screens.
- Verification data
- Only what is needed to confirm the one-time code: the method, provider, mode, and timing. Subscriber lookup data from the verification provider is not stored.
- Request metadata
- Coarse details such as the source website and a hashed form of the requester's network address. Raw addresses are not retained.
- Destination responses
- Truncated and sanitized before being recorded, so credentials and unnecessary personal data do not end up in evidence.
Safeguards in the product
Controls that are implemented today
- Tenant isolation enforced by database row-level security, not only by interface filtering.
- Role separation between organization administrators and analysts.
- Credentials for delivery destinations encrypted before storage and never returned in full to the interface.
- Outbound delivery restricted to HTTPS, with destination network checks that refuse internal or private targets.
- Revocation records and delivery attempt history stored append-only; corrections are new entries.
- Administrative and support access recorded as auditable events, including cross-organization access by revoq staff.
- Server-side rate limiting and expiry on one-time code verification.
Roles and responsibilities
Who is responsible for what
Your organization decides which websites and channels are covered, which destinations receive requests, what disclosure text consumers see, and who on your team has access.
revoq runs the verification and delivery path, applies the configuration you set, records the evidence, and makes that evidence readable.
Neither can guarantee what a downstream system does internally after it accepts a request. revoq reports the reply it received; interpreting that reply is your team's decision.
Retention and access requests
Open items to confirm with us
Retention periods, data residency, deletion timelines, and subprocessor details are agreed per organization and are not published here as blanket commitments. Ask for them directly and you will get the current answer in writing.
Security questions and vulnerability reports can be raised through the security page. Privacy questions are covered in the privacy notice.