Questions and answers for due diligence
The answers below are written so they can be pasted into a vendor assessment. Each answer links to the page that documents it. Where something is a limitation, that is stated.
Architecture and providers
Which language model is used, and who delivers it?
Anthropic Claude (claude-sonnet-4-6) for chat and document analysis. OpenAI for vectorisation of question text (text-embedding-3-small) and for voice mode (gpt-realtime). Revizo does not host any models itself. → Technical architecture
Is the model trained or fine-tuned on our data? No. Both providers are used under commercial API terms that exclude use of customer data for model training. Revizo does not train or fine-tune on conversations. → Data access
Does the model have access to the database? No. The model never gets a database connection, SQL, or ORM objects. It gets JSON results from named tools that Revizo runs with organisation ID from the logged-in session. → Architecture → Design principle
Where does the processing run? Revizo’s application on Vercel (Frankfurt), database at Supabase (Frankfurt). Model calls go to Anthropic and OpenAI in the USA. → Data access → Where data is processed
Which legal basis is used for transfer to the USA? The European Commission’s standard contractual clauses (SCC), GDPR Art. 46(2)(c). The transfer is limited to the context for the individual request. → Data Processing Agreement, Sub-processors
Can we get copies of Data Processing Agreements with the sub-processors? Yes. We send a provider pack with current agreement status per sub-processor on request. Contact karl@savesolutions.no.
Data access and data minimisation
Which data is sent to the model in a typical request? The user’s name, organisation, and role; which page the user is on; date; the conversation; name and role of up to 25 contacts; up to 10 short “memories” about the user; and the result of the tools the model asked for. Not the entire accounts. → Data access → What is included in one request
Can the assistant see data from other organisations?
No. All lookups are filtered on tenant_id from the session. An ID that belongs to another organisation gives an empty result, not an error and not foreign data. → Security controls → Control chain
Does the assistant respect task visibility (private tasks, team)? Yes. The task tools and the task context use the same visibility rule as the rest of Revizo. → Actions and tools
Are national ID numbers or bank account numbers sent to the model? The tools do not return these fields. In addition the model is instructed not to reproduce them, and the reply is filtered for the patterns. → Data access → What is never sent
Are attachments or file contents sent to the model? Not in ordinary chat. AI document analysis is a separate function that can be turned off separately, and sends only extracted text (max 15,000 characters). Screenshots the user pastes in the chat are sent as an image. → Data access
What is stored, and for how long? Conversations are stored in the organisation’s tenant for 90 days and are deleted automatically. The user can delete earlier. Memories expire per type (60–180 days). Export files from chat are deleted after 24 hours. Usage log and audit log are retained as long as the organisation is active. → Data access → What Revizo stores
Does the model provider store our requests? The providers process the request to deliver the reply under their commercial API terms. Revizo has not ordered storage with them and does not use the provider’s history. Current agreement status for retention is documented in the provider pack. → Data access → About retention at the provider
Authorisation and actions
How is the model prevented from doing something the user is not entitled to? The model can only propose tools from a fixed catalogue. Each tool runs with the user’s identity and organisation from the session, and verifies ownership before it reads or writes. The model’s arguments are proposals, not authorisation. → Architecture → Design principle
Can the assistant send email out of the organisation without anyone confirming? Documentation requests require that the user presses Send on a card. Kundetiltak send-outs require two-step confirmation with the number of recipients first. Two tools are confirmed in the conversation: a message to a registered contact, and a reconciliation report where the default recipient is the user themselves. All send-outs are logged with recipient. → Actions and tools → Note on outbound email
Which actions are executed directly, without a card? Actions in Revizo that the user explicitly asks for and is themselves entitled to: create and change tasks, run Smart Match once, create reminders, create exports. All are logged. → Actions and tools → Risk classes
Can the assistant write to our accounting system? Only if Tripletex actions are enabled for the organisation. Then it can create vouchers and invoices and approve supplier invoices when the user asks for it, with logging. The integration is optional. → Actions and tools → Tripletex
How do you handle prompt injection? We assume the model can be manipulated and design so that it does not give access: tenant filter in tools, visibility rules, confirmation cards, sanitisation of HTML, max 5 tool rounds, and stripping of fake tool syntax. The instruction to the model is not described as a security boundary. → Security controls → Prompt injection
Does the assistant give accounting or tax advice? No. It is instructed to give facts and refer to an auditor or Skatteetaten, the reply filter catches typical advice wording and adds disclaimers, and legal lookups go against Lovdata with a source citation. → Actions and tools → Fixed instructions
Control and governance
Can we turn AI off? Yes. An administrator can turn off all AI, or only chat, document analysis, or voice, under Settings → AI & Privacy. The server rejects requests to a turned-off function (fail-closed). The rest of Revizo is unaffected. → Security controls → Administrator controls
Can we restrict who uses it? The Viewer role cannot use chat. Members and administrators can. Quota per month is set by an administrator. → Access control
Which limits exist against abuse and cost runaway? 10 requests per minute per user, configurable monthly quota per organisation, max 5 tool rounds, limited reply length, 60-second timeout. → Architecture → Models and parameters
Is there an audit trail? Yes. Writing actions are logged in the organisation’s audit log with type, user, and timestamp. Each model call is logged with model, tokens, and tools used. → Security controls → Audit trail
What happens if the model provider is down? Chat replies with an error message. Reconciliation, tasks, import, reports, and the rest of Revizo work as normal. AI is not a critical dependency.
What happens in a security breach at you or a sub-processor? We follow GDPR Art. 33 and 34: the Norwegian Data Protection Authority (Datatilsynet) is notified within 72 hours, affected customers without undue delay. → Incident handling
Known limitations
What do you not claim? We do not claim that all data processing happens in the EEA — AI calls go to the USA. We do not claim that the instruction to the model is a security boundary. We do not claim that all outbound emails require a card — two tools are confirmed in the conversation. We do not claim that the rate limit is per organisation — it is per user. → Security controls → Limitations we are open about
Can you fill in our own questionnaire? Yes. Send a template or questionnaire (CAIQ, SIG, your own) to karl@savesolutions.no. We normally reply within 1–2 business days and attach a technical annex pack if needed.
Last updated: September 2026