Security

Permission is not the same as authorization.

Stripe Connect is easy to approve; RevRez still refuses every write until you explicitly activate resolution.

Audit-only application gate

Stripe Connect grants the account connection, while a separate RevRez execution gate blocks emails and Stripe writes before activation.

Restricted-key backup

Advanced users can provide a read-only restricted API key for the audit, then connect Stripe later to activate resolution.

Protected credentials

Provider tokens are encrypted at rest. Session secrets are random, hashed in storage, short-lived in transit, and sent only in secure, HTTP-only cookies.

Auditable actions

Decisions, token usage, supporting context, actions, and outcomes are recorded. Uncertain evidence and merchant gates stop execution.

Playbook-specific verification

Dunning and disputes are the core product. The AR add-on requires a verified Stripe business account, tax ID, and B2B attestation.

Infrastructure

The application runs on Cloudflare; payments and account data stay with purpose-limited processors including Stripe, Google, and Resend.

Start with AI-powered analysis

Find every failed payment and unresolved dispute.

Start your audit