Skip to main content

Security and privacy

Revizo is built for the accounting industry — an industry where trust, accuracy, and confidentiality are fundamental requirements. We process financial data and personal data on behalf of accounting firms and their clients, and we take this responsibility very seriously.

This section gives you a complete overview of how we protect data, meet regulatory requirements, and secure the platform.


Security in every layer​

Revizo is built with security in every layer of the platform — from code and authentication to database and infrastructure.

LayerProtection
Code and developmentESLint, TypeScript strict, CodeQL, automated tests, Dependabot, branch protection
AuthenticationIndustry-standard authentication via Clerk with SSO and MFA
AuthorisationRole-based access control (RBAC) with three levels
API securityInput validation, rate limiting, generic error messages
DatabaseTenant isolation, Row Level Security, encrypted storage
InfrastructureTLS in transit. Hosting and object location per system — see sub-processors
MonitoringReal-time error monitoring, structured logging, audit log

Key facts​

Data storageSupabase project stated in Frankfurt. AI is processed at Anthropic/OpenAI (USA, SCC) — see Revizo AI. R2 location is not confirmed.
Encryption in transitTLS 1.2+ on all communication
Encryption at restAES-256 on database and file storage
AuthenticationClerk (SOC 2 Type II certified)
Multi-tenancyFull isolation — no organisation can see another’s data
GDPRData export, right to erasure, 30-day grace period
BackupDaily automatic backup, point-in-time recovery
MonitoringSentry error monitoring with PII filtering

Documentation​

DocumentContent
Privacy and GDPRLegal basis, your rights, privacy notice
Data processing and storageWhere data is stored, how it flows, encryption
Access controlAuthentication, roles, access management
Sub-processorsWho processes data on our behalf
Security architectureTechnical security measures in detail
Incident handlingWhat we do in the event of a security breach
Data retentionHow long data is stored and deletion routines
SFTP file transferSecurity measures for automatic file import via SFTP
Revizo AI — security and architectureHow the AI assistant works, what it sees, how actions are authorised, and answers for IT and security

Due diligence and procurement​

For procurement or a security review, we can provide a technical annex pack (architecture, sub-processors, isolation, development practices, and gap register). Contact us at the email below — please include any template or questionnaire you want answered.


Do you have questions?​

If you have questions about security, privacy, or compliance, or need documentation for a procurement process, contact us:

We normally reply within 1–2 business days.


Last updated: April 2026