RevCert / security
Your team stays in control.
Who can access invoice data, which decisions require review, and what RevCert does not do automatically.
Current controls
- Private workspace: hosting access is owner-only. Server routes require platform-authenticated identity; records and documents are scoped to that identity.
- Server-side credentials: OAuth tokens are encrypted with AES-GCM before storage. Secret values do not belong in browser code or GitHub.
- OAuth state protection: expiring, single-use OAuth state is tied to the owner and a browser cookie.
- Explicit decisions: messages remain editable and are shared manually. Your team records invoice approvals and proposed offers in RevCert; suppliers must separately agree to new terms. Accounting updates and payment stay in your existing system.
- Change protection: version checks help prevent conflicting edits. Changed QuickBooks data is flagged for review.
- Limited supplier preview: seven-day, single-response links expose only selected invoice details—not internal context or attachments. External access is not enabled.
Not a certification claim
We do not claim SOC 2 certification, a completed penetration test, guaranteed uptime, or “bank-grade” security. The private workspace has not completed an independent security audit or production integration review.
Before customer rollout
Complete production OAuth validation, customer and supplier access controls, retention and deletion workflows, incident response, monitoring, backup and recovery testing, and approved legal terms.
Report a concern
Email khuranah.fp@gmail.com to report a concern. Do not send passwords, API keys, or unredacted financial documents.