Trust Center

Security & Compliance, Verified

Security is the foundation of our platform, not a feature. Here's everything you need to evaluate RevenueLoom for your enterprise.

Certifications & Compliance

Independently Audited

Our compliance is verified by third-party auditors, not self-attested.

SOC 2 Type II

Certified

Audited annually by an independent third party. Covers Security, Availability, and Confidentiality trust service principles.

  • Annual re-audit cycle
  • Covers Security, Availability, Confidentiality
  • No exceptions in latest report

ISO 27001

Certified

Information Security Management System (ISMS) certified. Demonstrates systematic approach to managing sensitive data.

  • ISMS certified by accredited registrar
  • Risk-based security management
  • Continuous improvement framework

GDPR

Compliant

Full compliance with EU General Data Protection Regulation. Data subject rights, lawful processing, and cross-border transfer safeguards.

  • Lawful basis: contract & legitimate interest
  • SCC and TIA for cross-border transfers
  • Automated DSR handling within 30 days

CCPA / CPRA

Compliant

Compliance with California Consumer Privacy Act and California Privacy Rights Act. Consumer rights, opt-out mechanisms, and data minimization.

  • Right to know, delete, opt-out
  • No sale of personal information
  • Service provider data processing agreement

Full audit reports available under NDA. Contact support@revenueloom.ai to request.

Platform Security

Defense in Depth

Layered security controls across data, infrastructure, access, and operations.

Data Encryption

  • AES-256 encryption at rest
  • TLS 1.3 for data in transit
  • Field-level encryption for PII and financial data
  • Customer-managed encryption keys (BYOK) available

Infrastructure

  • Single-tenant deployment with dedicated VPC
  • Private VPC peering and IP allowlisting
  • Configurable data residency (US, EU, APAC)
  • 99.9% uptime SLA with multi-AZ redundancy

Access Control

  • SSO via SAML 2.0 and OIDC
  • Role-based access control (RBAC)
  • Principle of least privilege enforced
  • Full audit logging with 7-year retention

Operational Security

  • Quarterly third-party penetration testing
  • Responsible disclosure program (support@revenueloom.ai)
  • Incident response plan with 24-hour notification SLA
  • Employee background checks and security training

Data Protection

Your Data, Your Rules

How we handle, protect, and respect your data.

Data Segregation

Every customer receives a dedicated, single-tenant instance. Your data is never co-mingled with other customers' data.

Data Ownership

You own your data. We process it solely to deliver the services you've contracted. We never use customer data to train shared models.

Data Deletion

Upon contract termination, all customer data is permanently deleted within 30 days. Deletion is verified and documented.

Sub-processor Transparency

We maintain a public list of sub-processors with 30-day advance notice of changes. Customers can object to new sub-processors.

Incident Response & Disclosure

1

Detection & Triage

24/7 monitoring with automated alerting. Incidents triaged within 1 hour of detection.

2

Customer Notification

Affected customers notified within 24 hours of confirmed incident, with ongoing updates every 72 hours until resolution.

3

Post-Incident Review

Full root cause analysis shared with affected customers within 14 days of resolution, with preventive measures documented.

Need more details?

We provide full security documentation, architecture diagrams, and audit reports under NDA.

Request Security Documentation