Security at Revnary

Built for finance teams who need to protect customer and revenue data.

Your data is never used to train models

We don't train, fine-tune, or share your data with any third-party AI providers. Your files are used only to generate your workbook.

Data residency

All uploads are processed and stored on AWS in the EU (Ireland). Backups remain within the EU.

File handling & retention

  • Files are encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Generated workbooks are stored securely for 30 days by default (configurable), then deleted.
  • You can delete files immediately from within the product; deletion propagates from active storage and scheduled backups.

Access controls

  • Role-based access; production data access is restricted to a small, audited group on a least-privilege basis.
  • Admin access protected by MFA and hardware-backed keys for engineering.

Infrastructure & monitoring

  • Hosted on Amazon Web Services (AWS) with network isolation, private subnets, and managed secrets.
  • Continuous logging of auth, file access, and exports; alerts for unusual activity.

Vulnerability management

  • Regular dependency patching and container image scans.
  • External penetration testing at least annually and after major changes.
  • A documented vulnerability disclosure process.

Business continuity

  • Encrypted backups with daily snapshots and tested restore procedures.
  • No single points of failure in the storage path for uploads and workbooks.

Data subject rights (GDPR)

  • We act as Processor; you remain Controller.
  • We support access, rectification, and deletion requests.
  • Data Processing Addendum (DPA) available on request.

Reporting a concern

Questions or need to report a security issue? Email hello@revnary.com