Security and privacy FAQ
The questions enterprise security teams ask most often during evaluation, answered up front.
These are the security, privacy and compliance questions we are asked most often by enterprise customers during evaluation. Publishing them is meant to shorten procurement and security review by settling the common ground up front.
For further information, see the Data Processing Agreement, the Intended Use, Limitations & AI Transparency documentation and our Trust Center, which carry the full detail behind these answers.
Have a specific questionnaire? Send it to support@revial.ai and we will complete it formally in your preferred format.
Company and contact
Who is the legal entity providing the service, and who do we contact about security and privacy?
The service is provided by Spinder Company Oy (Business ID 3384117-2), a Finnish limited liability company operating as Revial, with registered office in Oulu, Finland.
The primary contact for data protection and security questions is
support@revial.ai — prefix the subject with
[Security] or [Privacy] for fastest routing. Legal and contractual queries
go to the same address.
Certifications and attestations
Does Revial hold third-party security certifications (SOC 2, ISO 27001)?
ISO 27001 certification is in progress. The stage 2 audit is complete and final certification is pending our vendor's QA process.
Written policies and controls can be reviewed in the Trust Center.
Hosting and data residency
Where is customer data stored and processed?
Customer data is hosted in the European Union. The primary database is provided by Supabase (EU, Stockholm). Application hosting and serverless backend functions run on AWS Stockholm.
Encryption
How is customer data encrypted at rest and in transit?
In transit: TLS 1.2 minimum on all external connections, TLS 1.3 preferred and negotiated by default. Weak ciphers are disabled.
At rest: AES-256 for databases, object storage and backups. Encryption keys are managed through the cloud providers' key management services (AWS KMS), with restricted administrative access and provider-default key rotation. Backups containing personal data are encrypted to the same standard.
AI and LLM data handling
Do you use customer data to train or fine-tune AI models?
No. Customer data is never used to train, fine-tune or improve any AI model.
Sub-processors
Who are your sub-processors, and how are changes communicated?
The current sub-processor list is published in the DPA, with each provider's function and processing location.
We give written notice of additions or replacements at least 14 days in advance, allowing customers to object on legitimate grounds. Each sub-processor is bound by written contract to data protection obligations substantially equivalent to those between Revial and the customer — including confidentiality, security, onward sub-processor controls and assistance with data-subject rights.
GDPR and data processing
What is Revial's role under GDPR?
For customer personal data processed through the service, the customer is the controller and Revial (Spinder Company Oy) is the processor under GDPR Article 28. A Data Processing Agreement is in place before any personal data is processed.
Standard Contractual Clauses are used for international transfers via sub-processors located outside the EEA, supplemented where applicable by the EU-U.S. Data Privacy Framework.
Access control
How is access to the application and to customer data controlled?
Customer-side. SSO via SAML 2.0 and OIDC, integrated with your identity provider (Azure AD / Entra ID, Okta, Google Workspace). MFA is required for accounts that do not use SSO. Role-based access control on an Owner / Admin / Member / Read-only baseline, with custom roles on Enterprise plans. SCIM 2.0 provisioning and de-provisioning on Enterprise plans. Session timeout is configurable — 12 hours by default — with forced re-authentication for sensitive operations and immediate session invalidation on credential change.
Revial-side. Production access is restricted to a named subset of Revial engineers under least-privilege and need-to-know principles, gated through SSO with MFA, logged, and reviewed at least quarterly. Direct access to customer data without a documented support request or customer authorisation is prohibited under our acceptable-use policy.
Operations and monitoring
What logging and monitoring is in place?
Application and infrastructure logs are centrally collected, protected against unauthorised modification, and retained for 12 months by default.
Monitoring covers authentication events, administrative actions, access to customer data, repeated failed logins, unusual database queries, abnormal API usage patterns and resource anomalies, with automated alerts to the on-call engineer. Security alerts are triaged within one business hour during business hours and within four hours outside them.
Incident response and breach notification
How does Revial detect, respond to and notify customers about incidents?
Revial maintains a documented incident response plan covering detection, triage, containment, eradication, recovery, customer and regulator notification, and post-incident review.
In the event of a personal data breach affecting customer data, Revial notifies the affected customer without undue delay and in any event within 48 hours of becoming aware, with progress updates as the investigation continues. Notifications include the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed.
Post-incident reviews above defined severity thresholds are completed within 30 days, and findings feed into control improvements. Documentation is in the Trust Center.
Vulnerability management and penetration testing
How are vulnerabilities identified, prioritised and remediated?
Continuous automated scanning runs across the codebase and runtime: software composition analysis and dependency scanning on every commit, container and runtime configuration scanning, and secrets scanning in source control.
A third-party application penetration test is conducted at least annually, with the executive summary available under NDA.
Remediation targets, measured from confirmation:
| Severity | Target |
|---|---|
| Critical | 7 days |
| High | 30 days |
| Medium | 90 days |
Responsible disclosure reports go to
support@revial.ai with the subject prefix
[Security]. We acknowledge within two business days.
Secure software development lifecycle
How is security built into the development process?
All production code changes require peer review and must pass automated checks — linting, type checks, unit and integration tests, dependency scanning, secrets scanning — before merge. Production deployments go through CI/CD pipelines; no direct human write access to the production database is permitted under normal operations.
Engineers receive secure coding training at onboarding and at least annually thereafter, including AI/LLM-specific risks: prompt injection, data exfiltration via tool use, and output handling. Threat modelling is performed on new features that process customer personal data, integrate new third-party services, or expose new external interfaces.
Personnel security
How does Revial manage personnel security risks?
All employees and contractors sign confidentiality and intellectual-property agreements before being granted access to customer data. Background checks (criminal record and right-to-work, within the limits permitted by Finnish law) are conducted for personnel with production or customer-data access.
Security and data protection training is mandatory at onboarding and at least annually thereafter, covering GDPR principles, phishing and social-engineering awareness, secure handling of customer data, and AI-specific considerations. Phishing simulations run at least semi-annually.
Access is removed on the same business day as departure. Policy violations are addressed through documented disciplinary procedures.
Endpoint security
How are the devices used by Revial personnel secured?
Company-issued laptops are required for any production or customer-data access. All endpoints are enrolled in mobile device management, with enforced full-disk encryption (FileVault / BitLocker), enforced screen lock, automatic OS and security patching, endpoint detection and response software, and a documented acceptable-use policy. Lost or stolen devices can be remotely locked and wiped.
Personal (BYOD) devices are not permitted to store unencrypted customer data.
Business continuity and disaster recovery
What are the backup and recovery measures?
The primary Supabase Postgres database is backed up automatically, with continuous point-in-time recovery covering the previous 7 days and daily snapshots retained for 30 days. Application code, infrastructure-as-code and configuration are version-controlled in Git with full history retained.
Recovery objectives for the production service:
| Objective | Target |
|---|---|
| RPO — data loss tolerance | ≤ 1 hour |
| RTO — time to restore service | ≤ 8 hours |
Restore procedures are tested at least annually and documented in internal runbooks. Critical sub-processors are either redundant or have documented fail-over procedures.
Contract exit
What happens to customer data at the end of the contract?
During the contract, customers can export their data at any time via the application or, on request, as a structured export.
On termination, customer personal data is returned or deleted within 30 days, during which the customer can request a final export. After that period, unless retention is required by applicable law, personal data is deleted from production systems within a further 30 days, and from backups in line with backup retention cycles — no later than 90 days from termination. Written confirmation of deletion is provided on request.
Audit rights
What audit rights does the customer have?
On written request and at the customer's expense, the customer may audit Revial's DPA and GDPR compliance once per 12-month period. Audit reports are treated as Revial's confidential information.
We typically meet audit needs by providing security and compliance documentation — security overview, penetration test summary, CAIQ, and ISO 27001 once available — in lieu of on-site audit, with on-site audit available where a documented regulatory requirement exists.
Regulatory scope — the EU AI Act
How does Revial relate to the EU AI Act?
Revial's AI features are decision-support tools for sales teams. They do not process biometric data, do not infer emotions, do not make or support employment decisions, and produce no autonomous actions.
On current assessment, no Revial feature is classified as a high-risk AI system under Annex III of the EU AI Act. The classification of the Coaching Insights feature against Annex III point 4(b) — worker monitoring and evaluation — is addressed in detail in the AI Transparency documentation.