Security & trust

Autonomous where authorized. Human-controlled where consequential.

Revioli can understand customer operations and coordinate agents continuously because identity, tenancy, evidence, memory, permissions, policy, approval, and auditability are built into the system—not added after the AI.

REVIEW
READY
Controls mapped
Permissioned by design control set
AES
256
Encryption
TLS + AES-256
NO
TRAINING
Cross-customer training
Off by default
Autonomy posture
System accessRequired
Data scopeRequired
Tenant isolationScoped per tenant
Encryption in transitTLS
Encryption at restAES-256
Audit loggingLogged
Least-privilege accessRBAC + MFA
Shared training on your dataOff by default
Data deletion on requestSupported

Current certification status. Revioli does not claim a completed SOC 2 certification today. We can provide the current control set, architecture, data-flow boundaries, agent permissions, roadmap, and review documentation under NDA.

Agent control plane

No agent can expand its operating boundary silently.

Every source, field, transformation, memory artifact, tool, action, and approval path belongs to an explicit tenant policy. Revioli can operate continuously because the boundary is machine-enforced and reviewable.

01

System access

Your team approves every system Atlas and Revioli Agents may access: product, billing, CRM, support, documentation, warehouse, exports, and future tools.

02

Data scope

Atlas only retains approved fields and derived context. Sensitive data can be excluded, redacted, transformed, isolated, or placed under a shorter retention policy.

03

Company-model approval

Account, user, subscription, event, relationship, role, policy, and workflow mappings are reviewed before Brain Engine or any agent relies on them.

04

Action policy

Agents may investigate, prepare, route, and follow work inside policy. Customer-facing, financial, destructive, or permission-expanding actions require the approval level your company defines.

05

Audit trail

Data access, reasoning inputs, agent activity, approvals, handoffs, tool use, and outcomes remain reviewable so every operation can show what happened and why.

Hard system boundaries

What Revioli will never do silently.

Autonomy becomes useful only when its non-negotiable boundaries are explicit, enforced, and visible to the customer.

  • Revioli never fabricates customer history, evidence, actions, or outcomes.
  • Agents never treat unverified or unavailable evidence as fact.
  • Brain Engine never reasons outside the tenant evidence and policy boundary.
  • New tracking, tools, permissions, and customer-facing actions never activate silently.
  • Certification status, controls, incidents, subprocessors, retention, and deletion remain explicit during review.
Controls

The control plane is part of the intelligence system.

Tenant isolation

Each customer’s data is logically isolated, with boundaries enforced at the data and application layers.

Encryption

Data is encrypted in transit with TLS and at rest with AES-256, including backups where applicable.

Audit logging

Access and key actions are logged with timestamps and actor identity for review.

Agent and human access controls

Role-based access with least-privilege defaults and MFA for internal access.

Data retention

Retention windows for raw inputs and derived artifacts are defined during onboarding.

Deletion on request

You can request deletion of your data and model artifacts. We confirm completion and timelines in writing.

Backups & recovery

Encrypted backups and recovery procedures protect against accidental data loss.

Incident response

A documented incident-response process defines severity, ownership, escalation, and customer notification.

Security review readiness

We support vendor reviews with documentation, questionnaires, and an NDA-backed controls overview.

Data lifecycle

Every operation can show where data, memory, and authority stop.

Every stage is within policy, encrypted, and logged. Your approved data builds your living company model and agent context—not a shared cross-customer intelligence pool by default.

Ingest
over TLS
Isolate
per tenant
Encrypt
AES-256
Reason
within policy
Retain
defined window
Delete
on request

No shared company intelligence by default

Your data builds your model. We do not use it to train shared or cross-customer models unless you explicitly opt in, in writing.

Company intelligence remains tenant-bound

The company model, signal intelligence, customer memory, Brain Engine outputs, agent records, and Atlas mappings remain tied to your tenant and are included in deletion.

For your security team

Need to run vendor review before sending data?

We can support a serious review process with a controls overview, security questionnaire, subprocessor list, incident policy, and architecture summary under NDA.

Controls overview (Permissioned by design)
Security questionnaire (CAIQ-style)
Subprocessor list
Architecture & data-flow summary
Incident-response policy

Review the control plane before Revioli operates.

Define the systems, data, tools, memory, agent scope, and approval policies first. Then deploy Revioli through a rapid working session, private Atlas Agent, or live connections.