Restricted source permissions
Read-only Stripe requests limit what the connector can do with a billing relationship. Credentials belong in the supported server-side configuration path.
Security at Revioli
Your customer data deserves deliberate protection. Revioli limits source access, separates workspace records, sanitizes behavioral evidence, and keeps changes accountable to your team.
Protection throughout the data journey
Each stage has a specific purpose and a corresponding boundary. Explore how information becomes useful without granting the system unlimited access.
The Stripe connector uses restricted, read-only access for approved customer and subscription context. Its requests retrieve information; they do not issue charges, refunds, or subscription changes.
Credential values are resolved through server-side secret handling. Configuration stores references rather than exposing the credential in the public interface.
Atlas sanitizes behavioral evidence to remove sensitive credential and payment fields, direct identifiers, and unbounded free text. Approved product signals and their source context can then support analysis.
Customer identity and display information are handled through the authorized identity and account context. Sanitization of behavioral evidence is one layer of protection, alongside access and storage controls.
Tenant-scoped access and database policies restrict records to the authorized workspace. Source ownership checks help prevent an identity or source from being attached to the wrong tenant.
Raw storage buckets are private. Access to records and stored objects is controlled independently from whether a background service can process them.
Customer records · Source evidence · Private storage
No shared customer record view
Tracking and mapping activation require explicit approval; production trackers also require validation. Guarded mutations retain audit records so the decision can be inspected later.
Risk assessments and prepared recovery recommendations remain advisory. Your team owns customer contact and decides whether to make any billing or subscription change.
Retention and deletion are governed by our Privacy Policy, applicable agreements, and legal requirements. Access and deletion requests are reviewed through the contact path described in that policy.
Workspace records remain tenant-bound. Any use of de-identified, aggregated patterns for internal model improvement stays within the policy’s separate model-use provisions.
Controls with a clear purpose
Security works through connected controls. Source permissions, storage boundaries, sanitization, and approval checks address different parts of the data path.
Read-only Stripe requests limit what the connector can do with a billing relationship. Credentials belong in the supported server-side configuration path.
Workspace identity is enforced around records and stored objects. Raw Atlas storage is private and access is restricted.
Sensitive fields are filtered before they become behavioral evidence. Product activity is kept within its approved scope and source lineage.
Tracking and mapping changes require a recorded decision. Guarded changes keep audit records, and recommendations leave customer action with your team.
Connected customer records support Revioli within your workspace. They are not exposed as another customer’s records or used to train third-party public models.
De-identified, aggregated patterns may support internal model development and evaluation under our Privacy Policy. Identifiable shared-model use requires separate written permission.
Review the model-use policy ↗Ready for a proper security conversation
We’ll review your requirements against the actual connection and deployment you plan to use, including any gaps that need to be addressed before data is connected.
Yes. Share your source permissions, access, retention, and deployment requirements with our team. We will confirm the proposed data path and the documentation available for your review before you provide customer data.
We do not currently claim SOC 2 Type II or ISO 27001 certification. We describe the controls we implement and confirm certification status directly during your review.
Review transport protection, storage encryption, credential management, region, retention, and the specific hosting arrangement with us. Deployment-specific requirements such as customer-managed keys, VPC hosting, or on-premise operation require a separate scope review; they are not implied by connecting a source.
No. Recovery recommendations remain advisory. Your team reviews the evidence and owns customer contact, refunds, and subscription decisions. The Stripe connector itself is read-only.
Contact founders@revioli.com. We review requests under the Privacy Policy and applicable agreements. Please send a description of the request rather than credentials or customer records.
Trust starts with a clear conversation
Source access, isolation, model use, and data lifecycle should be understandable before you connect.