Revelara.ai

Security & Compliance

How we protect your data · Last updated: July 21, 2026

Revelara helps engineering teams find and prevent reliability risk. Because that work can touch source code and incident data, we treat the security of your data as foundational. This page summarizes how we protect it and where we are on our compliance roadmap. Our current subprocessors are listed in our Privacy Policy. To request a Data Processing Agreement or details of our security posture, email trust@revelara.ai.

Data handling model

Revelara is designed to minimize the data that ever leaves your environment.

  • Local-first analysis. The Revelara scanner and rvl CLI can run entirely within your own environment. In that mode your source code is analyzed locally and does not leave your infrastructure; only the risk findings you choose to share are transmitted.
  • Bring your own data. Where you connect data to the hosted platform, it is scoped to your organization and used only to provide the Service to you.
  • Data minimization. We collect the minimum needed to deliver risk analysis, and we do not sell customer data.

Infrastructure & application security

  • Tenant isolation. Every record is scoped to your organization and enforced at the database layer with PostgreSQL row-level security, so one organization can never read another's data. Our isolation controls are covered by an automated test suite.
  • Encryption in transit and at rest. All traffic is served over TLS. Data is encrypted at rest, and sensitive credentials are additionally encrypted at the application layer with AES-256-GCM.
  • Single sign-on and MFA. Authentication is via enterprise SSO (Google, GitHub, and Microsoft OAuth and SAML), so multi-factor authentication is enforced by your identity provider. Access is role-based and least-privilege.
  • Secrets management. Credentials are held in a managed secret store and are never committed to source control or container images.
  • Secure development. Changes ship through version control with automated tests, linting, and required checks, plus automated security scanning (static analysis, dependency, and container scanning) in our CI pipeline.
  • Hosting. The platform runs on Google Cloud Platform in a continuously reconciled, declarative configuration.
  • Backups and recovery. The production database is continuously backed up with point-in-time recovery and runs with a synchronous standby for high availability.
  • Monitoring. Systems are monitored with metrics, uptime checks, and alerting.

Compliance

  • SOC 2. Revelara is a young company and is actively working toward SOC 2 Type II. We are implementing the required controls and collecting evidence now; the report is not yet complete. We are glad to walk prospective customers and their security teams through our current posture and roadmap on request.
  • GDPR and data processing. A Data Processing Agreement is available on request. Our Privacy Policy describes how we handle personal data.
  • Subprocessors. A current list of the subprocessors we use to operate the Service is published in our Privacy Policy.

Reporting a vulnerability

We welcome responsible disclosure. If you believe you have found a security vulnerability in Revelara, email trust@revelara.ai with details and steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We will acknowledge your report and keep you updated on our progress.

Contact

For any security, privacy, or compliance question, or to request a DPA:

Revelara AI LLC
Security & Trust: trust@revelara.ai
Website: https://revelara.ai

© 2026 Revelara AI LLC. All rights reserved.
Open Source FAQ Privacy Security Terms Cookies Acceptable Use Contact