Security boundary

What Revvye can touch.

Revvye reads the same public surface a buyer or search crawler can see. It does not sign in, collect site credentials, or reach private systems.

Report a security issue

Policy reviewed August 2, 2026

scan-boundary / public-webenforced
Access classPUBLIC

No login. No private-system access.

target normalizationprivate network rejectionrate limiting

01 / boundary ledger

A narrow footprint by design.

The strongest control is the one the product does not need. Revvye limits what enters the scan path before infrastructure protections have to carry the load.

01

Public surface

In scope

Public HTML, robots.txt, sitemaps, metadata, structured data, and observable performance signals.

02

Private systems

Out of scope

Customer accounts, CRMs, booking internals, payment systems, and private network addresses.

03

Site credentials

Never requested

There is no credential entry in the scan flow and Revvye does not bypass access controls.

04

Card data

Handled by Stripe

Checkout is Stripe-hosted. Revvye retains receipt-level metadata, not full card numbers.

02 / data handling

Collect less. Retain with limits.

Scan artifacts are retained for 12 months from the scan date, or until a deletion request, whichever comes first. Account data is kept while an account is active plus 90 days after a deletion request, except where law requires retention.

Read the privacy policy
Scan artifacts12 months maximum

Public-page evidence and scan results.

Account deletionActive term + 90 days

Subject to records Revvye must legally retain.

Processing vendorsPublished ledgerView subprocessors

03 / disclosure

Good-faith research has a direct path.

Report suspected vulnerabilities to security@revvye.com. Include enough detail to reproduce the issue and allow a reasonable investigation window before public disclosure.

Revvye does not pursue legal action against good-faith research that respects user privacy and avoids service disruption.

04 / known limits

No certification theater.

Revvye does not currently hold SOC 2 or ISO 27001 certification and does not claim otherwise. Its posture rests on a narrow data footprint, public-only scanning, reputable infrastructure vendors, rate limits, target validation, and least-privilege production access.