Security

Security at Revorva

How we keep your data — and your customers' data — safe.

You can also email the founders directly at founders@revorva.com — we read and reply to every message.

Stripe connection security

We connect via Stripe's official OAuth — the same way you'd authorise Slack, Notion, or any trusted Stripe app.

We request only the minimum permissions needed:

  • Read failed payment data
  • Trigger payment retries
  • Read customer email addresses for recovery emails

We never request access to your Stripe balance or payouts.

Data encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Database hosted on Supabase with bank-level security infrastructure.

No customer card details ever touch our systems — Stripe handles all sensitive payment data.

Access control

Only authorised Revorva systems have access to your data.

All employee access is logged and audited.

Multi-factor authentication required for all team members.

Where your data lives

Data is stored in EU and US data centres (depending on your region).

We are GDPR-compliant for EU customers.

Data is never sold, shared, or used for marketing other products.

Incident response

In the unlikely event of a security incident, affected customers are notified within 72 hours per GDPR requirements.

Security contact: security@revorva.com

Compliance

Operating under Humanaira Ltd, registered in England and Wales.

Address: 167–169 Great Portland Street, London, W1W 5PF, UK

VAT registered, ICO registered for data protection compliance.

Responsible disclosure

Found a security issue? We welcome responsible disclosure.

We aim to respond within 48 hours.

Email: security@revorva.com

Security is an ongoing commitment, not a checkbox. If you have questions about how we handle your data, email us at security@revorva.com.