Trust & compliance

Security at RevIQ

Revenue infrastructure runs on trust. RevIQ is built on controls partners can verify — encryption everywhere, least-privilege access, and continuous monitoring — so the teams who route spend and inventory through us can check our practices, not just take our word for it.

Last updated luglio 2026 · security.txt

Compliance & certifications

RevIQ operates under GDPR and CCPA / CPRA. We are working toward SOC 2 Type II attestation, and ISO 27001 certification is in progress. Our latest penetration-test summary and the current subprocessor list are available to customers and prospects under NDA: request the documentation directly.

How we secure your data

These are the practices that protect your data, and they run continuously:

  • Encryption: TLS 1.2+ in transit and AES-256 at rest, with managed key rotation.
  • Least-privilege access: SSO, enforced MFA, and role-scoped access reviewed on a regular cadence.
  • Continuous monitoring: centralized, tamper-evident audit logs with automated alerting on anomalous activity.
  • Testing: independent annual penetration tests plus continuous dependency and image scanning.

Secure SDLC, incident response, subprocessor governance, and backup & recovery detail are documented in our security controls documentation, available to customers under NDA on request.

Data, privacy & residency

Personal data moves through RevIQ under region-aware consent (CMP / TCF) honored end to end, with data minimization: we collect only what the service requires. We support GDPR and CCPA / CPRA data-subject requests, and a Data Processing Agreement (DPA) is available to every customer.

You choose where your data lives. Pin a workspace to the United States or the European Union at setup: operational data stays in the region you pick, while a small set of account metadata is always handled in the US. The choice is permanent.

Transparency

Verify rather than take our word for it: request our reports and controls documentation under NDA, and watch the platform in real time on our status page.

Reporting a vulnerability

We welcome reports from security researchers and triage every submission. Good-faith research is authorized; we won’t pursue legal action for it. Email security@rev.iq or read our security.txt.

FAQ

Is my data encrypted?

Yes. Everything is encrypted in transit with TLS 1.2+ and at rest with AES-256, and keys are rotated under management.

How can I access, export, or delete my data?

Email security@rev.iq with a data-subject request and we’ll process access, transfer, or deletion in line with GDPR and CCPA / CPRA.

Can I review your security documentation?

Yes — our controls documentation and latest penetration-test summary are shared with current and prospective customers under NDA. Contact us to request them.