Revv · Trust Center

Revv Trust Center

Trust center

Revv maintains a public trust center documenting ISO 27001:2013, SAS 70 / SOC 2, ISO 27001:2013, SAS 70 / SSAE 16, PCI DSS, and GDPR compliance.

CompanyDocument AutomationElectronic SignatureContract ManagementSales EnablementWorkflow AutomationSaaS
Trust center: https://www.revv.so/trust/security.html

Certifications & Compliance

ISO 27001:2013SAS 70 / SOC 2ISO 27001:2013SAS 70 / SSAE 16PCI DSSGDPR

Source

Trust Center

revv-trust-center.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.revv.so/trust/security.html
url: https://www.revv.so/trust/security.html
title: Revv Trust Center — Security & privacy center
note: >-
  The automated probe (probe-security-programs.py) missed this page because it lives at
  /trust/security.html rather than trust.<domain> or /trust; it was found by reading the
  site navigation and confirmed by fetch (HTTP 200, 2026-08-14). Read the certification
  list carefully: most of the named certifications belong to Revv's SUPPLIERS, not to
  Revv. The page states AWS data centres are ISO 27001:2013 / SAS 70-SSAE 16 / PCI DSS
  certified and GDPR compliant, that payment card handling is Stripe's PCI DSS scope, and
  that eSignature legal compliance is delivered "in partnership with OneSpan". Of Revv's
  OWN posture the page says only that Revv "is building its system to be compliant with
  ISO 27001:2013 and SAS 70 (SOC 2) standards with the certification work under review".
  That directly contradicts the product pricing page, which claims "SOC2 Compliance — our
  app and infrastructure is SOC2 certified"; the discrepancy is recorded, not resolved.
certifications:
- name: ISO 27001:2013
  holder: Revv
  status: in-progress
  claim: '"building its system to be compliant ... with the certification work under review"'
- name: SAS 70 / SOC 2
  holder: Revv
  status: disputed
  claim: >-
    trust/security.html says "under review"; pricing.html says "our app and
    infrastructure is SOC2 certified"
- name: ISO 27001:2013
  holder: Amazon Web Services (hosting provider)
  status: inherited
- name: SAS 70 / SSAE 16
  holder: Amazon Web Services (hosting provider)
  status: inherited
- name: PCI DSS
  holder: Stripe (payment processor) / AWS
  status: inherited
  claim: Revv does not process credit card information; Stripe handles payments
- name: GDPR
  holder: Amazon Web Services (hosting provider)
  status: inherited
regulatory_compliance:
- ESIGN Act (US)
- UETA (US)
- eIDAS / Regulation 910/2014/EC (EU)
- Information Technology Act 2000 (India)
esignature_partner: OneSpan Sign
security_practices:
- Data at rest encrypted in AWS RDS via AWS KMS (FIPS 140-2 validated HSMs)
- S3 server-side encryption (SSE-S3)
- AWS CloudTrail key-usage logging
- Periodic internal infosec/compliance audit on a 6-month cadence
- Security policy review with remediation steps
contacts:
  security: security@revvsales.com
  support: support@revv.so
related:
  privacy_policy: https://www.revv.so/privacy.html
  terms_of_use: https://www.revv.so/termsofuse.html
  data_processing_agreement: https://www.revv.so/data-processing-agreement.html
x-evidence:
- url: https://www.revv.so/trust/security.html
  status: 200
  fetched: '2026-08-14'
  keywords:
  - trust center
  - compliance
  - iso 27001
  - soc 2
  - pci dss
  - gdpr
  - encryption
- url: https://www.revv.so/pricing.html
  status: 200
  fetched: '2026-08-14'
  keywords:
  - soc2 compliance