Trust & Security
Revantex sits on your storefront and talks to your customers, so security isn’t a feature — it’s the foundation. Here’s how we protect the data you trust us with, and exactly who we rely on to run the service.
We never train AI on your data
Conversations are processed only to answer your customers — never used to train AI models.
SOC 2–certified infrastructure
Built entirely on SOC 2 Type II providers; card data is handled by Stripe (PCI DSS).
Encrypted & isolated
TLS in transit, encryption at rest, and per-tenant row-level isolation in the database.
All traffic is served over TLS and HSTS is enforced. Data at rest lives in managed Postgres and object storage that is encrypted by default.
Every tenant's data is separated by Postgres Row-Level Security, keyed to the authenticated account — one tenant can never read another's inventory, leads, or configuration.
Concierge API keys are stored only as SHA-256 hashes, never in plaintext. Service-role credentials are server-only and never reach the browser.
Inbound billing webhooks are signature-verified before they're trusted, and scheduled jobs are protected by a shared secret. Concierge-supplied URLs are sanitized to block script injection.
Responses ship strict security headers — Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, and frame protections — and public endpoints are rate-limited.
The concierge confirms a visitor's consent before storing their contact details, and visitor PII is kept out of plaintext logs.
We use a small set of trusted infrastructure providers to deliver Revantex. Each processes only the data needed for its function, under its own security and privacy commitments.
| Provider | Purpose | Data processed |
|---|---|---|
| Anthropic | AI model — concierge & search responses | Conversation content |
| Voyage AI | Embeddings for catalog search | Catalog text |
| Supabase | Database & file storage | Config, inventory, leads |
| Clerk | Dashboard authentication | Account identity |
| Stripe | Billing & payments | Billing & customer data |
| Resend | Transactional email | Recipient email, lead content |
| Upstash | Rate limiting | Request metadata |
| Vercel | Hosting & edge network | All request traffic |
Revantex runs on fully managed, auto-scaling infrastructure — there are no servers for us to forget to patch, and capacity grows automatically with your traffic.
Served from a global edge network on serverless infrastructure that scales with demand — no fixed capacity to outgrow or over-provision.
Hosting and database run on SOC 2–certified platforms with automated backups and redundancy; uptime is inherited from these providers rather than bespoke infrastructure.
If a non-critical dependency has a hiccup, the concierge keeps answering and degrades gracefully — a dependency issue never takes your storefront assistant down.
Prompt caching and retrieval keep AI cost and response times stable as your catalog and conversation volume grow.
For the visitor and lead data your concierge collects, you are the data controller and Revantex is the processor — we handle that data only to provide the service to you, never to train models or for our own marketing.
Data Processing Agreement. A DPA is available on request for customers who need one — email mir@revantex.com.
Retention & deletion.Inventory, configuration, and leads are retained for as long as your account is active, and conversation transcripts are kept for 90 days. You can export your leads at any time from the dashboard, and we’ll delete your data on request when you close your account.
Data subject requests.If one of your customers asks to access or delete the details they shared with your concierge, contact us and we’ll help you fulfill it.
Found a security issue? We want to hear about it. Email mir@revantex.com with the details and we’ll respond promptly. Please give us a reasonable window to remediate before any public disclosure.
Last updated June 25, 2026