Security

The security behind
your AI associate.

Built so your credentials never touch the AI, every send waits for your approval, and your data never trains a model.

Approval before every sendNever trains a modelAES-256-GCM credentialsPer-workspace isolation

Security & data handling at Revr · Last updated July 2026

01 · The risks

An AI associate creates new risks.
Here’s how we handle them.

Reggie reads your pipeline and runs your outreach, so Revr is built to a higher bar than a normal CRM. Not a policy. The architecture.

Reggie drafts. You approve. Then it sends.

Every outreach email and text Reggie writes lands in your review queue as a draft — you approve, edit, or skip it.

  • Approval enforced server-side: an already-sent draft can’t fire twice.
  • Automations default to draft-for-review; auto-send exists only where you deliberately turn it on.
  • Sequences pause the moment a contact replies.
Command Center · Drafts
To: J. Whitman, Summit Wealth Partners
“Saw your Brickell lease runs out in July, I have two 12k SF options worth a look…”
Approve & sendEditSkip
02 · The boundaries

What Revr does.
What Revr does not.

Here’s exactly what Revr touches, and what it never does.

Does
Encrypts everything
TLS in transit. Encryption at rest. AES-256-GCM application-layer encryption for every customer credential and OAuth token.
Waits for your approval
Every Reggie-drafted email and text sits in your review queue until you approve, edit, or skip it — enforced server-side.
Sends as you
Email goes out from your own verified domain; SMS through your own Twilio account. Replies land in your real inbox.
Isolates every workspace
Row-level security on every table. Your records are scoped to your account on every read and write.
Does not
Train on your data
Your pipeline, contacts, and messages never enter a training set — not ours, not our AI provider’s.
Read your inbox uninvited
Connecting a mailbox so Revr can send from it never lets Revr read it. Reading is a separate switch, off by default, and turning it back off deletes what was read. Gmail is send-only and cannot be read at all.
Store card numbers
Payments are handled entirely by Stripe. Revr never stores or even sees your card details.
Lock in your book
Your pipeline, contacts, and voice are yours — exportable to CSV any time, and they follow you to any firm.
03 · The honest status

Built first.
Certified as we scale.

The controls are real today; the paperwork is catching up. Here’s the status of each, no badge inflation.

Encryption in transit & at rest
Live
TLS on every connection; encrypted storage; AES-256-GCM application-layer encryption for customer credentials.
Architecture walkthrough available
Per-workspace isolation (RLS)
Live
Row-level security enforced in the database plus application-level scoping on every read and write.
Architecture walkthrough available
Approval-before-send queue
Live
Server-side approval gate on all Reggie-drafted outreach; duplicate-send protection.
Live in every account
Mailbox reading is opt-in
Live
Gmail is send + calendar only and holds no inbox-read scope. Outlook can be read only after you switch it on in Settings; message bodies are deleted after 90 days and switching it off erases everything stored.
Verifiable on the OAuth consent screen and in Settings
Data Processing Agreement (DPA)
On request
Signed DPA for firm and enterprise accounts.
security@getrevr.com
SOC 2
In progress
Readiness underway; third-party attestation as we scale.
Report shared after certification
04 · The stack, named

No mystery vendors.

Who touches your data, by name, and what you control.

Where your data lives

Supabase (managed PostgreSQL) and Vercel, both US-hosted. Secrets live only in server-side environment variables — never in client code or the repository.

A named model provider

Reggie runs on Anthropic’s Claude — named here, not “leading AI models.” Only the records relevant to the task you invoke are sent, under a commercial API that does not train on inputs.

Your controls

Export everything to CSV any time. Request deletion whenever you want — your workspace is wiped within 30 days. Disconnect any integration to delete its credentials immediately.

The full subprocessor list ships in our compliance pack, request it, a vendor security review, or a DPA at security@getrevr.com.

05 · Straight answers

The questions security teams ask.

Asked by brokers, IT departments, and lawyers. Answered without the hedging.

No. Every outreach email and text he drafts lands in your review queue, and the approval gate is enforced server-side — an already-sent draft can’t fire twice, and automations default to draft-for-review. Auto-send exists only where you deliberately turn it on, and you can turn it off any time.

Have a security team?

We’ll walk them through the architecture, complete a vendor security review, and provide a DPA on request.

Contact us about security

See also security.txt, our Privacy Policy, and Terms.