Security at Revnary

Built for finance teams who need to protect customer and revenue data.

Your data is never used to train models

We never use your data to train AI models. For automated column mapping and service period detection, anonymised column headers and small description samples may be sent to Google Gemini (Google Cloud AI). This is governed by Google's API Terms of Service, which prohibit using API data for model training. Your revenue figures and full transaction data are never sent externally.

Third-party AI usage

For automated column mapping and service period detection, anonymised column headers and small description samples may be processed by Google Gemini (a Google Cloud AI service). Revenue figures and full transaction rows are not shared. Google's API terms prohibit using this data for model training.

Data residency

Files are stored on Google Cloud in the EU. Core processing runs on Google Cloud Run in the EU. Backups remain within the EU.

File handling & retention

  • Files are encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Generated workbooks are retained for 90 days after job completion (or until you delete them), then permanently removed.
  • You can delete files immediately from within the product; deletion propagates from active storage and scheduled backups.

Access controls

  • Role-based access; production data access is restricted to a small, audited group on a least-privilege basis.
  • Admin access protected by MFA and hardware-backed keys for engineering.

Infrastructure & monitoring

  • Backend compute runs on Google Cloud Run with network isolation and managed secrets. Uploaded files and generated workbooks are stored on Google Cloud Storage in the EU region.
  • Continuous logging of auth, file access, and exports; alerts for unusual activity.

Vulnerability management

  • Regular dependency patching and container image scans.
  • External penetration testing at least annually and after major changes.
  • A documented vulnerability disclosure process.

Business continuity

  • Encrypted backups with daily snapshots and tested restore procedures.
  • No single points of failure in the storage path for uploads and workbooks.

Data subject rights (GDPR)

  • We act as Processor; you remain Controller.
  • We support access, rectification, and deletion requests.
  • Data Processing Addendum (DPA) available on request.

Reporting a concern

Questions or need to report a security issue? Email hello@revnary.com

Have a specific compliance or data handling question? We're happy to provide a Data Processing Addendum (DPA). Request a DPA →