Public surface
In scopePublic HTML, robots.txt, sitemaps, metadata, structured data, and observable performance signals.
Security boundary
Revvye reads the same public surface a buyer or search crawler can see. It does not sign in, collect site credentials, or reach private systems.
Report a security issuePolicy reviewed August 2, 2026
No login. No private-system access.
01 / boundary ledger
The strongest control is the one the product does not need. Revvye limits what enters the scan path before infrastructure protections have to carry the load.
Public HTML, robots.txt, sitemaps, metadata, structured data, and observable performance signals.
Customer accounts, CRMs, booking internals, payment systems, and private network addresses.
There is no credential entry in the scan flow and Revvye does not bypass access controls.
Checkout is Stripe-hosted. Revvye retains receipt-level metadata, not full card numbers.
02 / data handling
Scan artifacts are retained for 12 months from the scan date, or until a deletion request, whichever comes first. Account data is kept while an account is active plus 90 days after a deletion request, except where law requires retention.
Read the privacy policyPublic-page evidence and scan results.
Subject to records Revvye must legally retain.
03 / disclosure
Report suspected vulnerabilities to security@revvye.com. Include enough detail to reproduce the issue and allow a reasonable investigation window before public disclosure.
Revvye does not pursue legal action against good-faith research that respects user privacy and avoids service disruption.
04 / known limits
Revvye does not currently hold SOC 2 or ISO 27001 certification and does not claim otherwise. Its posture rests on a narrow data footprint, public-only scanning, reputable infrastructure vendors, rate limits, target validation, and least-privilege production access.