generated: '2026-08-14' method: searched probe: true source: https://www.revv.so/trust/security.html url: https://www.revv.so/trust/security.html title: Revv Trust Center — Security & privacy center note: >- The automated probe (probe-security-programs.py) missed this page because it lives at /trust/security.html rather than trust. or /trust; it was found by reading the site navigation and confirmed by fetch (HTTP 200, 2026-08-14). Read the certification list carefully: most of the named certifications belong to Revv's SUPPLIERS, not to Revv. The page states AWS data centres are ISO 27001:2013 / SAS 70-SSAE 16 / PCI DSS certified and GDPR compliant, that payment card handling is Stripe's PCI DSS scope, and that eSignature legal compliance is delivered "in partnership with OneSpan". Of Revv's OWN posture the page says only that Revv "is building its system to be compliant with ISO 27001:2013 and SAS 70 (SOC 2) standards with the certification work under review". That directly contradicts the product pricing page, which claims "SOC2 Compliance — our app and infrastructure is SOC2 certified"; the discrepancy is recorded, not resolved. certifications: - name: ISO 27001:2013 holder: Revv status: in-progress claim: '"building its system to be compliant ... with the certification work under review"' - name: SAS 70 / SOC 2 holder: Revv status: disputed claim: >- trust/security.html says "under review"; pricing.html says "our app and infrastructure is SOC2 certified" - name: ISO 27001:2013 holder: Amazon Web Services (hosting provider) status: inherited - name: SAS 70 / SSAE 16 holder: Amazon Web Services (hosting provider) status: inherited - name: PCI DSS holder: Stripe (payment processor) / AWS status: inherited claim: Revv does not process credit card information; Stripe handles payments - name: GDPR holder: Amazon Web Services (hosting provider) status: inherited regulatory_compliance: - ESIGN Act (US) - UETA (US) - eIDAS / Regulation 910/2014/EC (EU) - Information Technology Act 2000 (India) esignature_partner: OneSpan Sign security_practices: - Data at rest encrypted in AWS RDS via AWS KMS (FIPS 140-2 validated HSMs) - S3 server-side encryption (SSE-S3) - AWS CloudTrail key-usage logging - Periodic internal infosec/compliance audit on a 6-month cadence - Security policy review with remediation steps contacts: security: security@revvsales.com support: support@revv.so related: privacy_policy: https://www.revv.so/privacy.html terms_of_use: https://www.revv.so/termsofuse.html data_processing_agreement: https://www.revv.so/data-processing-agreement.html x-evidence: - url: https://www.revv.so/trust/security.html status: 200 fetched: '2026-08-14' keywords: - trust center - compliance - iso 27001 - soc 2 - pci dss - gdpr - encryption - url: https://www.revv.so/pricing.html status: 200 fetched: '2026-08-14' keywords: - soc2 compliance