Security & compliance

Enterprise security for agentic finance

Rever connects read-only, keeps write credentials away from agent runtimes, and holds every external action for human approval.

SOC 2 Type II
Annually audited
ISO/IEC 27001:2022
Certified
AES-256 + TLS
At rest and in transit
Five regions
Or your own perimeter
One approval path

Agents prepare. You approve.

Rever can investigate, reconcile, and draft. Nothing posts or leaves the company until a person approves it.

01 · Read

Source systems stay unchanged

Rever reads your ERP, banks, and documents without writing back.

02 · Prepare

Every number keeps its evidence

Agents reconcile, trace, and draft. Preparer is never approver.

03 · Approve

Your signature releases the work

The approval key never enters an agent runtime.

Security & deployment

A clear baseline, wherever Rever runs

Security baseline
  • Read-only by default

    ERP, bank, and document connections begin without write access.

  • Write keys stay out of agent runtimes

    Agents prepare work. Only the audited approval path can post it.

  • Customer data stays customer data

    Your records never train models used by another tenant.

  • Every decision can replay

    Sources, evidence, approvals, and outcomes remain on one trail.

  • Identity is centrally managed

    SSO, SAML, and SCIM are available for enterprise access control.

  • Preparer is never the approver

    No agent or person approves work they prepared. Duties separate by design.

  • Dual approval on material amounts

    Material postings and payments require two human signatures before they move.

Deployment
Managed

Rever Cloud

Tenant-isolated and region-pinned.

Dedicated

Private VPC

Single tenant with in-region model routing.

Self-hosted

Rever Reserve

The full platform inside your perimeter.

Bring your security team

Review the SOC 2 Type II report, ISO/IEC 27001:2022 certificate, architecture, controls, and data-processing terms.