Security & limits

It reads. It never writes.

You are pointing an AI workforce at your entire customer base. So the limits are architectural, not settings — there is no admin toggle that turns them off, because the permission to do those things was never requested.

01

Read-only, permanently

Every connection Revioli makes is read-only. It cannot write, refund, cancel, or change anything in the systems you connect — on any plan, at any tier, for any customer.

▪ enforced by the credential scope you issue
02

Nothing reaches a customer without you

Agents draft. Humans send. Every outbound message stops at an approval gate and waits — there is no autonomous-send mode to enable, and no plan that unlocks one.

▪ the approval gate is in the pipeline, not the UI
03

Your data stays yours

Raw records and workspace-specific learning remain private. Revioli may use de-identified, aggregated patterns to improve its internal models without identifying you or your customers.

▪ tenant isolation + bounded de-identified improvement
How data moves

One direction only.

Your systemsStripe · CSV
support · product
RevioliAtlas + Brain Engine
reasons, never writes back
Your queueevidence + drafts
waiting for a human
✕  There is no return arrow. Nothing Revioli produces is written back into your systems automatically.
Straight about our stage

What we have, and what we don't — yet.

We are an early company in a private rollout. Plenty of vendors imply certifications they don't hold. Here is the honest list, so your security review starts from the truth.

Read-only access to every connected sourceIn place
Human approval required before any customer contactIn place
Encryption in transit and at restIn place
Per-workspace data and model isolationIn place
Source lineage on every claim — auditable back to the recordIn place
Data deletion on requestIn place
SOC 2 Type II certificationNot yet
VPC or on-premise deploymentNot yet
Data residency selectionNot yet
SCIM / SSO provisioningNot yet

If a "not yet" is a blocker for you, say so before you sign up — we will tell you honestly whether it is on the near roadmap or not.

Straight answers

Security questions, answered plainly.

What access do you actually need?

A restricted, read-only Stripe key, or CSV exports. Nothing that grants write, refund, or account-change permission. If a scope isn't needed to reason about retention, we don't ask for it.

Can an agent email my customer by mistake?

No. Drafting and sending are separate stages, and the send stage requires a human action. An agent cannot reach the send stage on its own — that isn't a policy we apply, it's how the pipeline is built.

Do you use our data to improve models?

Customer-specific calibration stays inside your workspace. Revioli may use de-identified, aggregated patterns to train and evaluate its internal models, but it does not pool raw customer records, expose your data to another customer, or let a third-party public model train on identifiable Customer Data without separate written permission. The exact boundary is in our Privacy Policy.

Where does the language model fit in?

Language models propose candidate signals for you to approve, and draft message text. They never score your customers and never touch the decision math — that's the Brain Engine, which is a company-specific decision engine, not a chatbot.

Can we delete our data?

Yes, on request, including the calibration derived from it. Ask and we do it — no retention clause holding your data hostage.

Questions first, signup later

Send your security review our way.

We would rather answer hard questions before you connect anything than after. Reply to any address on this site and a founder answers.