Security

Designed with security and control in mind.

Reverto operates inside your lead sources, CRM and communication channels, which makes access control, data handling and oversight part of the implementation rather than an afterthought. Scope, permissions and controls are agreed with your team before anything is activated.

Four controls in every implementation.

Role-based access

Permissions are scoped to what each user and integration actually needs. Access is defined during implementation and reviewed as your workflows change.

Controlled integrations

Reverto connects only to the systems and data your organisation approves, with the minimum permissions required for each workflow.

Activity logging

Messages, decisions, handoffs and status changes are recorded, giving your team a reviewable trail of what the system did and why.

Human oversight

Sensitive workflows can be routed for review, and any conversation, campaign or workflow can be paused or taken over manually.

Documentation available for review.

Information Security Policy

How Reverto manages access, infrastructure, monitoring and incident handling.

View policy

Privacy Policy

What personal data is collected, how it is used and the rights available to individuals.

View policy

Data Processing Addendum

The contractual terms governing Reverto's processing of personal data on behalf of customers.

View DPA

Responsible AI Policy

How AI is applied within Reverto workflows, including scope limits, human oversight and escalation requirements.

View policy
Responsible AI

Scope limits are set before launch, not after.

Defined scope. Reverto operates within messaging, questions and subject matter your organisation approves. Out-of-scope conversations escalate to a person.
No autonomous decisions on sensitive matters. Clinical, legal, financial and other regulated judgements remain with qualified people on your team.
Human escalation paths. Urgent, distressed, high-value and uncertain conversations route to a named person with full context.
Reviewable output. Every automated interaction is logged and available for your team to review.

Additional controls where you need them.

For larger, regulated or technically complex organisations, implementations can include dedicated environments, custom integration reviews, advanced access controls, custom reporting and a formal security and compliance review as part of scoping.

Discuss enterprise requirements

Security FAQ

Where is our data processed and stored?

Reverto runs on established cloud infrastructure. The specific processing locations, storage arrangements and any sub-processors involved depend on your integrations and workflows. These are confirmed in writing during implementation and documented in our Data Processing Addendum.

Do you sign a DPA?

Yes. Reverto's Data Processing Addendum is available for review and forms part of the agreement.

Do you hold any security certifications?

Our security controls — access management, integration permissions, activity logging and human oversight — are set out in our Information Security Policy. If your procurement process requires formal certification evidence or a completed security questionnaire, raise it during scoping and we will confirm our current position and work through your review process.

Can we restrict which systems Reverto accesses?

Yes. Integrations, permissions and data scope are agreed during implementation and can be limited to specific systems, records or fields.

Can we remove access or pause the system?

Yes. Access can be revoked and workflows paused at any time.

Who can see our conversation data?

Access is scoped by role, and the permissions model is confirmed with your team during implementation.

Reviewing Reverto with your security team?

We can provide policy documentation, integration detail and a scoped implementation plan for review before any commitment.

Request security documentation