Security Measures
Last updated September 29, 2026
Rever Finance Inc.
This page describes the technical and organisational measures Rever applies to protect Customer Data and Personal Data, and how responsibility is shared in each deployment option. It is referenced by Section 14.1 of the Terms of Service, Section 6 and Annex II of the Data Processing Agreement, and the Service Level Agreement. Rever may update these measures from time to time, provided the overall level of protection is not materially reduced during a Subscription Term.
1. Security programme and attestation
Rever operates an information security programme built around the SOC 2 Trust Services Criteria and the ISO/IEC 27001:2022 control framework. A SOC 2 Type II examination is conducted annually and Rever holds ISO/IEC 27001:2022 certification. Reports and certificates are available under non-disclosure agreement on request through rever.ai/trust.
The attestation scope covers the Managed cloud and Private cloud deployments that Rever operates and the corporate controls that support them. Self-host environments are operated by the customer and are outside that scope, except for the software Rever delivers.
2. Deployment options and shared responsibility
| Area | Managed cloud | Private cloud | Self-host |
|---|---|---|---|
| Infrastructure operation | Rever, tenant-isolated | Rever, single-tenant in the customer's chosen region | Customer |
| Application security and patches | Rever | Rever | Rever provides; Customer applies |
| Backups and disaster recovery | Rever | Rever | Customer |
| Identity and access to the platform | Customer administrators; Rever support access under Section 4 | Same as Managed cloud | Customer |
| Connected System credentials and permissions | Customer | Customer | Customer |
| Data location | United States by default; other regions where offered, as recorded in the Order Form | The agreed region, with model routing and processing locations specified in the Order Form | Customer's perimeter |
| Availability commitment | SLA | SLA | None (customer-operated) |
3. Data handling controls
- Read-only connections. Connections to ERP, banking and document sources are established read-only. Write credentials, where a customer enables permitted workflows, are held outside agent runtimes.
- No financial action without approval. Financial actions, including postings, invoices, credit notes, payments, external communications and payment holds, execute only through permitted workflows after an authorised approver's recorded approval in the Inbox. Every payment hold requires approval before it is placed. No configuration removes this requirement.
- Evidence preserved. Original records are stored as received before any transformation. Findings, calculations and approvals link to their source records, and approval and evidence records are written to durable storage before the corresponding action is confirmed.
- No training on Customer Data. Neither Rever nor its model providers use Customer Data, or the inputs and outputs of AI Features, to train or fine-tune models. Business context kept within a customer's tenancy is stored as data and does not change model weights.
- Personal data in model context. Personal data in connected records is handled without human-readable exposure in model prompts and is not stored in model context.
- Tenant isolation. Each customer's data is logically separated at every layer. Instruction-based and model-based guardrails apply to every agent.
- Encryption. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Keys are managed through the cloud provider's key management service. Customer-managed keys are available where agreed in the Order Form.
4. Access control
- Role-based access control and least privilege for Rever personnel, with multi-factor authentication enforced for all administrative access.
- Access to production systems and customer tenants is logged and reviewed at least quarterly. Support access to a customer tenant requires authorisation and is recorded.
- Rever personnel may work from the United States and India. Access from any location is subject to the same controls, contractual confidentiality obligations and logging.
- Customers control their own users and roles, including preparer, approver and auditor roles. Single sign-on (SAML or OIDC) and SCIM provisioning are available on the Enterprise plan.
5. Infrastructure and application security
- The platform is hosted on Amazon Web Services for Managed cloud and Private cloud deployments, using network isolation, firewalls, intrusion detection and hardened images. The rever.ai website is hosted on Vercel.
- Secure development practices: code review, dependency monitoring and patching, secrets management, and vulnerability assessments with penetration testing at least annually.
- Logging and monitoring of infrastructure, application and security events, with alerting on anomalies.
- Encrypted backups taken daily with periodic restore testing, and documented disaster recovery procedures for Rever-operated deployments.
6. Incident response and severity classification
Rever maintains an incident response procedure with the following security severity levels. They are distinct from the support response targets in the SLA.
| Severity | Definition | Response |
|---|---|---|
| Security Sev-1 | Confirmed or credibly suspected unauthorised access to Customer Data or Personal Data, or a platform-wide security failure | Immediate containment, customer notification under Section 9 of the DPA, root-cause summary on request |
| Security Sev-2 | A contained security event with no confirmed access to Customer Data, or a material control failure | Investigation within one business day and notification where the DPA or law requires it |
| Security Sev-3 | A vulnerability or control gap with no evidence of exploitation | Remediation on a risk-based schedule |
Personal Data Breaches are notified to affected customers without undue delay, and in any event within seventy-two (72) hours of Rever becoming aware, as described in Section 9 of the DPA.
7. Organisational measures
Employee background checks where permitted by law, security awareness training, confidentiality agreements, change management, vendor due diligence and contractual safeguards for every sub-processor listed at rever.ai/legal/sub-processors, and business continuity planning.
8. Customer responsibilities
Customers are responsible for the accuracy of their approval configuration, the permissions granted to Rever in Connected Systems, the security of their own user credentials and devices, and, for Self-host, the security of the environment in which the software runs, as described in the Terms and the Self-Hosted Software License.