How is Revomo hosted?
As a multi-tenant service on Amazon Web Services, in a multi-availability-zone configuration, with production logically segmented from development and staging. The application database is MongoDB Atlas, hosted in AWS.
How is our data encrypted?
In transit with TLS 1.2 or higher, and at rest with AES-256 or equivalent. Cryptographic keys are held in a dedicated key management service with restricted access.
How are roles and permissions managed?
An organization holds its own data and workspaces partition it inside that organization. Roles are granted per resource, so access to price lists, pricing models, datasets and views is given separately rather than as one blanket permission. Access follows least privilege, with unique user identifiers and no shared credentials.
Does Revomo support enterprise single sign-on?
Contact us to review this requirement against your identity provider. We publish only what our current documentation supports, and single sign-on for customer tenants is not among the measures described in our Data Processing Addendum.
How are pricing and commercial actions governed?
Rulesets hold floors, corridors and eligibility as decision tables the business owns. Approvals route by value, region or threshold, and an exception is routed rather than absorbed. Prices, agreements and programs carry effective dates, so a change has a date as well as a value.
Is there audit history and lineage?
Datasets can keep row-level change history, and the platform maintains a dependency graph across entities: what a figure depends on, and what would break if it changed. Approvals and price actions are recorded against the objects they affect.
How are AI and agent actions controlled?
Agents work inside the same commercial context, permissions and approval thresholds as any other capability. An action that would need a person’s approval still needs it when an agent proposes it. AI inference runs through Amazon Bedrock, which is listed as a subprocessor.
Is our data used to train AI models?
Your data is used to provide, support, secure and improve the Service. Separately, the agreement permits Revomo to use aggregated and de-identified data, including to train and improve models, but only in a form that does not identify and cannot reasonably be used to identify you, your users or your customers. If you need a narrower commitment, raise it during contracting.
How does Revomo connect to our ERP, CRM and data platforms?
Through scheduled file exchange, direct API integration and connections to warehouse and lakehouse sources, managed in the Revomo cloud. Ask us about a specific system and we will tell you which pattern applies rather than assume one.
What happens to our data when we leave?
For 30 days after expiry or termination you may request a copy of your data in a commercially reasonable format. After that period it is deleted from active systems in the ordinary course, subject to backup retention schedules and any legal hold.
What deployment or data-residency options exist?
The Service runs as a multi-tenant application on AWS, and the subprocessors in our DPA are located in the United States. Contact us to review residency or deployment requirements beyond that.
Where can our security team find documentation?
The Trust Center carries the current posture and documentation. The Subscription Agreement, SLA, DPA and capacity schedule are published in full on this site, and the SOC 2 Type II report is available on request under confidentiality once per calendar year.