Security & Trust

Built to handle your revenue data carefully.

RevPass touches your most sensitive systems — your CRM, your contracts, your bookings. Here's how we protect them, and exactly who else is in the loop.

Encrypted in transit and at rest

All traffic runs over TLS. Data is encrypted at rest by our infrastructure providers, and connected credentials (Salesforce, Slack) are additionally encrypted at the application layer with AES-256-GCM.

Domain-locked access

Sign-in is Google SSO, restricted to verified accounts on your company domain. Personal and consumer email accounts are blocked.

Least-privilege Salesforce access

RevPass requests only the Salesforce scopes it needs to run your deals, and every write the agent makes is recorded.

Full audit trail

Key deal actions — validations, approvals, order-form generation, signing, and booking — are logged with who, what, and when, so every change is attributable.

You decide what runs on its own

An autonomy dial lets you require human review on every email and action, or hand specific steps to the agent. Nothing is automated beyond the level you set.

Separated, isolated tenants

Each organization’s data is scoped to that organization. We never combine your data with another customer’s, and never reuse it commercially.

AI & your data

Your data trains your deals — not someone's model.

RevPass runs on Anthropic's Claude under commercial terms. Under those terms, your data is not used to train AI models. We send only the deal context needed to do the work, and the agent's output is yours.

Because AI can make mistakes, a human stays in the loop by design. RevPass surfaces what it drafts and what it intends to change; you decide how much it does on its own, and every action it takes against your Salesforce is logged and reversible by your team.

Sub-processors

Who else touches your data

We keep our list of sub-processors transparent. Salesforce and Slack appear only when you choose to connect them.

ProviderPurposeData
VercelApplication hostingApp traffic
SupabasePrimary database (Postgres)Customer & deal data
Cloudflare R2File / document storageOrder forms & uploads
AnthropicAI model (Claude)Deal context sent for processing
ResendTransactional emailEmail address & message content
StripeBilling & paymentsBilling contact & payment metadata
GoogleAuthentication (SSO)Login identity
SalesforceCRM (you connect it)CRM records you authorize
SlackNotifications (you connect it)Messages you authorize
DocuSignE-signature (you connect it)Signer & document data

Today

  • TLS in transit; encryption at rest; AES-256-GCM for connected credentials
  • Google SSO with company-domain access control
  • Audit trail across deal actions
  • You own your data — export or delete it on request
  • We handle customer data as a service provider, in line with CCPA/CPRA

On our roadmap

  • SOC 2 (Type I → Type II)
  • Third-party penetration test
  • Formal Data Processing Agreement (DPA) for customers
  • Published security overview for vendor reviews

Mid-market evaluation under way? Reach out — we'll share our current security overview and where we are on each item.

Security questions?

We're happy to walk your security team through our architecture, controls, and roadmap.