Skip to main content

FAQ — Security

Short answers to common questions about security and privacy. For complete documentation, see Security and privacy.


Where is data stored?​

All data is stored in the EU (Frankfurt, Germany) at Supabase (AWS). We do not use data centres outside the EU for primary data processing.

See Data processing and storage for details.

Is the data encrypted?​

Yes, in several layers:

  • In transit: TLS 1.2+ on all communication (HSTS enabled)
  • At rest: AES-256 encryption on database and file storage
  • Application level: API tokens for accounting systems are encrypted with AES-256-GCM before storage

See Security architecture for technical details.

Who has access to my data?​

Only users who have been invited to your organisation. You decide who has access and which role they have:

  • Administrator — Full access including user administration and deletion
  • Member — Can create and edit, but not delete or manage users
  • Viewer — Can only view data and reports

No other organisations can see your data. See Access control.

Can data leak between organisations?​

No. Revizo uses three independent isolation mechanisms:

  1. Organisation ID is taken from the authenticated session, never from the URL
  2. All database queries automatically filter on your organisation ID
  3. Row Level Security (RLS) in the database provides an extra safety net

Do you support two-factor (MFA)?​

Yes. All users can enable two-factor authentication via user settings. We support authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) and SMS codes.

Can I export all data?​

Yes. All members of the organisation can download a complete data export (ZIP file with JSON and CSV) from Settings → Danger zone → Export all data.

See Data retention for details.

Can I delete all data?​

Yes. Administrators can schedule deletion of the organisation with a 30-day grace period. After the grace period everything is deleted permanently — database data, files, integrations.

See Deleting an organisation and account for step-by-step guidance.

What does the AI assistant see, and is it safe to use?​

Revizo AI only sees data in your organisation, and only what is needed for the question — not the entire accounts. It can only do things through predefined tools that run with your logged-in identity. Email out of the organisation requires that you press Send on a card. Data is not used to train models. An administrator can turn AI off under Settings → AI & Privacy.

Model calls go to Anthropic and OpenAI in the USA under EU standard contracts; accounting data and conversation archives are in Frankfurt.

See Revizo AI — security and architecture for full documentation, including questions and answers for IT and security.

Who are your sub-processors?​

We use recognised, security-audited services such as Supabase, Clerk, Vercel, Stripe, Sentry, and Cloudflare — all with SOC 2 certification and GDPR compatibility.

See Sub-processors for the complete list.

What happens in a security breach?​

We follow GDPR Articles 33 and 34. In a confirmed breach we notify the Norwegian Data Protection Authority (Datatilsynet) within 72 hours and affected customers without undue delay.

See Incident handling for our complete procedure.

Do you have a Data Processing Agreement (DPA)?​

Yes. Contact us at karl@savesolutions.no to establish a Data Processing Agreement.


Complete documentation​

For detailed information about all security and privacy measures, see our complete Security and privacy section.