Security and privacy
Where data lives, who can see it, what we claim and what we do not.
This page says what Revyn does with your data in plain terms, including the things we are not yet in a position to claim. The legal versions are the privacy policy and the terms of service.
#Where data lives
- Application data (accounts, deals, transcripts, scores) is in a managed PostgreSQL database.
- Recordings and documents are in object storage, keyed to your workspace.
- Knowledge-base embeddings and the knowledge graph are in dedicated stores, also keyed to your workspace.
- Infrastructure is hosted on major cloud providers. The application layer runs in multiple regions with automatic failover.
Data is encrypted in transit (TLS 1.2 or higher everywhere) and at rest.
#Who can see what
Within a personal workspace, only you. Revyn staff do not read your transcripts; support access to an account is granted per request, logged, and time-limited.
Within an org workspace, visibility follows roles:
- Members see their own calls, debriefs and Ask Revyn sessions, and the leaderboard.
- Managers see their team's calls and debriefs, and team analytics.
- Admins and owners see everything in the org, including the audit trail.
- Coaching cues are private to the rep on every plan.
Between workspaces, nothing. Org and personal accounts are separate; see Workspaces. Between orgs, the only shared number is the Revyn Index, which is k-anonymised and opt-out.
#AI models and training
Revyn uses third-party language, speech and voice models to run calls and answer questions. Your transcripts, documents and recordings are sent to those providers to be processed and are not used to train models shared with other customers. We contract with providers on terms that prohibit training on customer data. We do not train our own foundation models on your data.
Deterministic parts of the product (scoring rules, commitment logic, framework ceilings) run on our own servers and send nothing anywhere.
#Access controls
- Sign-in by Google, Microsoft, or email with a one-time code; optional password; single sign-on on Custom.
- Role-based permissions with custom roles, enforced on the server for every request.
- An org audit trail of membership, role, document, integration and export events.
- Integration tokens stored encrypted; write-back to external systems is off by default.
#Retention and deletion
Your data is retained while your account is active. Delete a recording, a document or a session and it is removed from the primary stores immediately and from backups on their normal rotation. Delete an account or an org and everything in it follows the same path. Request deletion from Settings → Account or by email to hello@revyn.in.
#Compliance: what we claim and what we do not
- India's DPDP Act: we operate as a data fiduciary under the Digital Personal Data Protection Act and honour its rights of access, correction and erasure.
- SOC 2: our audit is in progress. We will say so plainly until it is complete, and we will publish the report when it is.
- GDPR: we honour data-subject rights for EU users and offer a data-processing agreement on request. We do not yet claim full GDPR programme compliance.
- HIPAA: Revyn is not a HIPAA-covered product. Do not import calls containing protected health information.
If you need a security questionnaire answered or a DPA signed, write to hello@revyn.in.
#Reporting a vulnerability
Email hello@revyn.in with "Security" in the subject. We acknowledge promptly and do not pursue researchers acting in good faith.
Something missing or wrong on this page? Tell us.