Security and privacy
Revizo is built for the accounting industry — an industry where trust, accuracy, and confidentiality are fundamental requirements. We process financial data and personal data on behalf of accounting firms and their clients, and we take this responsibility very seriously.
This section gives you a complete overview of how we protect data, meet regulatory requirements, and secure the platform.
Security in every layer
Revizo is built with security in every layer of the platform — from code and authentication to database and infrastructure.
| Layer | Protection |
|---|---|
| Code and development | ESLint, TypeScript strict, CodeQL, automated tests, Dependabot, branch protection |
| Authentication | Industry-standard authentication via Clerk with SSO and MFA |
| Authorisation | Role-based access control (RBAC) with three levels |
| API security | Input validation, rate limiting, generic error messages |
| Database | Tenant isolation, Row Level Security, encrypted storage |
| Infrastructure | TLS in transit. Hosting and object location per system — see sub-processors |
| Monitoring | Real-time error monitoring, structured logging, audit log |
Key facts
| Data storage | Supabase project stated in Frankfurt. AI is processed at Anthropic/OpenAI (USA, SCC) — see Revizo AI. R2 location is not confirmed. |
| Encryption in transit | TLS 1.2+ on all communication |
| Encryption at rest | AES-256 on database and file storage |
| Authentication | Clerk (SOC 2 Type II certified) |
| Multi-tenancy | Full isolation — no organisation can see another’s data |
| GDPR | Data export, right to erasure, 30-day grace period |
| Backup | Daily automatic backup, point-in-time recovery |
| Monitoring | Sentry error monitoring with PII filtering |
Documentation
| Document | Content |
|---|---|
| Privacy and GDPR | Legal basis, your rights, privacy notice |
| Data processing and storage | Where data is stored, how it flows, encryption |
| Access control | Authentication, roles, access management |
| Sub-processors | Who processes data on our behalf |
| Security architecture | Technical security measures in detail |
| Incident handling | What we do in the event of a security breach |
| Data retention | How long data is stored and deletion routines |
| SFTP file transfer | Security measures for automatic file import via SFTP |
| Revizo AI — security and architecture | How the AI assistant works, what it sees, how actions are authorised, and answers for IT and security |
Due diligence and procurement
For procurement or a security review, we can provide a technical annex pack (architecture, sub-processors, isolation, development practices, and gap register). Contact us at the email below — please include any template or questionnaire you want answered.
Do you have questions?
If you have questions about security, privacy, or compliance, or need documentation for a procurement process, contact us:
- Email: karl@savesolutions.no
- Subject: Security / Compliance
We normally reply within 1–2 business days.
Last updated: April 2026