Security and integrity

Permission is not the same as authorization.

Connections provide data access. Separate application gates, merchant policy, and packet verification decide whether RevRez can act.

Audit-only application gate

Stripe Connect establishes the account connection, while a separate RevRez gate blocks emails and Stripe writes until explicit activation.

Capture before interpretation

Imported source records and artifacts are content-addressed in private object storage. Database records retain hashes and pointers used to verify provenance.

Approved, versioned mappings

AI may propose how fields should map. A merchant approves the mapping, and deterministic code replays that version for future records.

Packet integrity

Every evidence packet is versioned and hashed. RevRez verifies the hash before submission so review and execution refer to the same packet.

Idempotent action receipts

External actions are recorded once with sanitized request and response receipts, including the Stripe request identifier when available.

Protected credentials and model boundaries

Provider credentials are encrypted and excluded from evidence artifacts and model prompts. Only the context needed for a specific mapping or drafting task is sent to the relevant service.

Fail-closed review

Missing evidence, source conflicts, unsupported high-risk facts, policy conditions, and customer replies can stop automation and route work to a person.

Purpose-limited infrastructure

RevRez runs on Cloudflare and uses purpose-limited providers including Stripe, Google, and Resend for payment data, compute, identity, and email.

Start with an audit-only connection

See the backlog before RevRez can act.

Start your audit