Security and compliance at Revenium

Revenium meters usage metadata, not payloads. Compliance artifacts, encryption, data handling, subprocessors and platform controls are documented below.

Last reviewed 6 August 2026
Compliance

What we hold, and how to get it

Current as of 6 August 2026.

ArtifactStatusAccess
SOC 2 Type II reportHeldUnder NDA
Penetration test summary verify cadenceHeldUnder NDA
Architecture and data-flow diagramHeldUnder NDA
Business continuity planHeldUnder NDA
Data Processing AgreementHeldPublic
Subprocessor listHeldPublic
Terms of Service, SLA, Privacy PolicyHeldPublic
Your Data

What Revenium sees. And what it never sees by default.

Most AI observability tools sit in the request path and read everything that passes through. Revenium is built the other way around. The platform captures usage metadata only.

  • Token counts, input and output
  • Model, provider and latency
  • Computed cost and duration
  • Attribution fields: organization, subscriber, product, agent, task, workflow
  • Optional quality and classification metrics
  • Prompt content, never accessed by default
  • Response content, never stored by default
  • User-generated content, never analyzed by default

Payload capture is a per-organization opt-in, gated three ways: team admin enablement, per-user view access, and dedicated data contexts. When enabled, payload data is encrypted at rest.

Data Handling

Encryption, residency, retention and disclosure

ENCRYPTION

AES-256 and TLS 1.2+

All customer data is encrypted at rest using AES-256. Data in transit is encrypted with TLS 1.2 or higher, including across public networks. Credentials are stored hashed and are not retrievable by Revenium personnel.add key management

RESIDENCY

US by default, EU available

Customer data is processed and stored in US-based cloud infrastructure by default. An EU region is available on Enterprise plans.

RETENTION

Configurable, deleted on exit

Retention is configurable on Enterprise plans. On written request or on termination we provide a copy of your data and securely destroy our own copies, other than data we are legally required to retain and copies in backups until overwritten in the normal cycle.

ACCOUNT DATA

What a login holds

A Revenium account holds a business email address used as the username, an optional display name, role and permission assignment, authentication metadata, and IP addresses in access and audit logs. Authentication is delegated to Clerk, Inc. Revenium personnel cannot view credentials.

DISCLOSURE

72-hour breach notice

We notify affected customers by email without undue delay and within 72 hours of becoming aware of a breach, as committed in our published Data Processing Agreement.

PERSONNEL

Screened before access

Before any employee or contractor receives access to customer data, we run a background check covering criminal history over the prior five years and verification of employment and education history over the prior five years.

AI & Models

Where AI is used, and where it isn't

Buyers running AI risk assessments ask the same six questions. Here they are, answered.

The platform does not depend on a model

Metering, cost calculation, attribution and billing are deterministic. Their accuracy does not vary with model performance, so there is no model accuracy figure to report for the core use case.

Models are used on the insight layer only

Large language models are used for summarization and insight generation on top of already-computed data. Model providers are Anthropic and OpenAI, both listed on our public subprocessor page.

Your data does not train anything

Customer data is not used by Revenium or its affiliates to train, fine-tune or improve any model, and is not provided to any model provider for training.

Every insight is traceable

AI-generated insights trace back to the underlying metered transaction records. You can drill from a recommendation into the raw usage and cost data that produced it, so conclusions can be verified against source data rather than taken on trust.

Assessed, and reassessed

Revenium's AI use has been reviewed under enterprise AI model impact assessment processes, including automated approval through OneTrust. Use of the AI layer is reassessed every six months.

Guardrails are opt-in and explicit

Policy enforcement runs only where you configure a rule. Nothing is blocked, rewritten or intercepted unless you have asked for it.

Subprocessors

Published, not on request

Fourteen subprocessors span cloud infrastructure, authentication, payments, monitoring and engineering support. The published list names each one with its purpose and processing region.

We give 30 days notice before adding or replacing a subprocessor. Customers may object on reasonable data protection grounds within 15 days of notice.

View the subprocessor list →
CATEGORIES

What they do

  • Cloud infrastructure, hosting and databases
  • Authentication and identity management
  • Payments and billing
  • Workflow orchestration
  • AI model inference
  • Monitoring, uptime and error reporting
  • Engineering and product tooling
Platform

Enterprise controls confirm tiers and feature names

Controls available to administrators in the product.

  • Single sign-on: SAML 2.0 and OpenID Connect / OAuth 2.0
  • Role-based access control
  • Multi-factor authentication
  • Audit logging of user access and administrative actions
  • Configurable data retention
  • Customer-managed provisioning and deprovisioning
Availability

Uptime and resilience

Service level

Our published SLA commits to 99.99% monthly availability, with service credits below 99.95%.confirm before citing

Read the SLA →

Live status

Current and historical uptime is published continuously, not summarized once a quarter.

status.revenium.ai →

Audited controls

Availability controls were assessed under the SOC 2 availability criterion as part of our Type II audit.

Business continuity

Summary available under NDA.hold: not yet written

Disaster recovery

Summary available under NDA.hold: not yet written

Incident response

Summary available under NDA. Incident response was in scope for our SOC 2 Type II audit.hold: not yet written

Secure Development

How the SDK behaves, and how it's built

Asynchronous by design

SDK metering runs on a background thread after your model call returns. It never blocks the provider call and adds no measurable latency.

The only synchronous path is an optional pre-call guardrail check, which runs only when you configure an enforcement rule.

Dependencies tracked

Third-party open-source components in the platform and in published SDKs are tracked and scanned. A software bill of materials for published SDK packages is available on request.hold: SBOM not yet generated

Attestation

A CISA Secure Software Development self-attestation covering published SDK packages is available on request.hold: not yet produced

The Security Package

Everything procurement asks for, in one download

SOC 2 Type II report · penetration test summary · architecture and data-flow diagram · subprocessor list · Data Processing Agreement

Access is granted after a clickthrough NDA and domain verification. No countersignature, no waiting on us.requires gated access to be built

FAQ

Frequently asked questions

Is Revenium SOC 2 compliant?

Yes. Revenium holds a SOC 2 Type II report, issued after an independent audit against the AICPA Trust Services Criteria for security, availability and confidentiality. The report is available under NDA.

Do you hold ISO 27001?

Not today. SOC 2 Type II is our current attestation. We publish what we hold and what we do not.

Does Revenium store my prompts or AI responses?

Not by default. Revenium meters usage metadata only: tokens, cost, model, provider, latency, duration and attribution fields. Payload capture is a per-organization opt-in. When enabled, payload data is encrypted at rest and gated at the team, user and data-context level.

Is my data encrypted?

Yes. All customer data is encrypted at rest using AES-256, and in transit using TLS 1.2 or higher.

Where is my data stored?

In US-based cloud infrastructure by default. An EU region is available on Enterprise plans.

Will Revenium process personal data about my employees?

That is your choice. Attribution fields are populated by you, and we do not require individual identifiers. If you use pseudonymous values such as team or cost center, no personal data enters the platform through attribution. Platform accounts themselves hold a business email address, role and authentication metadata for each user you invite.

Is our data used to train AI models?

No. Customer data is not used by Revenium or its affiliates to train, fine-tune or improve any model, and is not provided to model providers for training.

Who are your subprocessors?

Fourteen, published with purpose and processing region. We give 30 days notice before any change and you may object within 15 days.

Does Revenium sign DPAs?

Yes. Our DPA is public, incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, and includes CCPA service-provider terms.

How quickly will you tell us about a breach?

Within 72 hours of becoming aware, by email, as committed in our DPA.

What happens to our data when we leave?

On request or on termination we provide a copy and securely destroy our copies, other than data we are legally required to retain and copies in backups until they are overwritten in the normal cycle.

Does adding Revenium's SDK put my AI traffic at risk?

No. SDK metering runs on a background thread after your model call returns. It adds no measurable latency and never blocks the provider call. The only synchronous step is an optional pre-call guardrail check, which runs only when you configure an enforcement rule.

Do you support SSO?

Yes. SAML 2.0 and OpenID Connect / OAuth 2.0, alongside role-based access control and audit logging.

How do I get the SOC 2 report?

Request the security package on this page. Access is granted after a clickthrough NDA and domain verification.

Filling out a vendor assessment?

SOC 2 report, penetration test summary, architecture diagram, DPA and subprocessor list, in one download.

Get the security package →

Evaluating the SDK?

See what the SDK sends, field by field, in the documentation.

Read the integration docs →

Question we didn't answer here?

Get our security team on a call with yours.

security@revenium.ai →

Meter your AI economics.
Keep your data yours.

Revenium gives engineering and finance teams control over AI spend without taking custody of your content.

SOC 2 TYPE II · FINOPS FOUNDATION

Internal — remove before publication

Amber markers in the page above correspond to the items below. Nothing amber should ship.

Blocks launch

  1. security@revenium.ai must be provisioned. Address is approved and now live as a mailto in the Contact section. The mailbox still needs to be created and monitored before launch.
  2. Penetration test cadence contradicts itself. Page copy says annual, a recent draft questionnaire response says quarterly. One figure, everywhere.
  3. Availability section contradicts the compliance table. Business continuity is now listed as Held in the table, but the Availability section still shows a held-back BC card. Un-hold that card, or downgrade the table row. The DR and IR cards stay held until those summaries exist.
  4. Secure Development section contradicts the compliance table. It still says the SBOM and the CISA self-attestation are "available on request." Both were removed from the public table this pass because they do not exist. Rewrite or remove those two cards before launch.

Needs an owner to confirm

  1. Business continuity plan is shareable. Confirmed as held. Confirm it is in a form that can go out under NDA before the table row ships.
  2. Key management detail for the AES-256 claim, for example AWS KMS with managed rotation. Engineering.
  3. SSO plan tier, audit logging and retention feature names. Product. The Platform Controls list cannot publish without this.
  4. 99.99% SLA figure. Confirm the status page history supports repeating it on a trust page. If measured uptime is lower, cite the commitment and link the status page rather than implying achieved performance.
  5. Deletion window including backups. Engineering, before we commit to a number.
  6. No breach in the past 24 months. Jason Cumberland to confirm in writing. Not published on this page, but it is being asserted in questionnaires.

Still needed, no longer promised publicly

Removed from the public compliance table this pass. The work is still required, we have just stopped advertising the gap.

  1. CAIQ. Free self-assessment, preempts most bespoke questionnaires, and the single highest-leverage artifact on the list.
  2. SBOM and CISA self-attestation for published SDK packages. Required by any customer embedding the SDK. See blocker 4.
  3. Disaster recovery and incident response summaries. Most-requested artifacts we cannot produce, and they are blocking live enterprise reviews.
  4. ISO/IEC 27001 and 42001. Not held and no longer disclosed on the page. Expect these to come back as direct questions in questionnaires. Prepare a standard answer.

Build to finish the page

  1. Clickthrough NDA and domain-verified download. The package band promises it. Until it exists, the flow is still a manual request.
  2. Move to trust.revenium.ai. The DPA, Terms, SLA, subprocessor and status pages are all on .ai.

Defects on pages this one links to

  1. Terms of Service Governing Law reads "[State/Country]". An unfilled template placeholder on a live public page. Any reviewer who opens the Terms will find it. Fix first.
  2. Terms of Service last updated 30 May 2025 and does not reference the DPA or SLA, though the DPA states it is incorporated into the Terms.
  3. DPA Exhibit A points Annex III at https://Company.com/help/subprocessors/, a leftover placeholder pointing at a domain we do not own. Tables 1 and 2 are also unpopulated.
  4. Domain drift. The SLA support contact is support@revenium.io while the legal pages sit on revenium.ai.

Publishing constraint

  1. Do not name customers. Several executed enterprise NDAs prohibit disclosing that discussions are taking place, not only the information exchanged. The AI section says "enterprise AI model impact assessment processes" deliberately. Logos and case studies need prior written consent in every case.

Changed in this pass (v3.1)

  1. Hero. Kicker removed, headline made declarative, subhead cut to one sentence, second CTA dropped, five-tile badge strip removed entirely.
  2. Auditor no longer named. Badge and FAQ both now read "independently audited" rather than naming the firm.
  3. Compliance table cut from twelve rows to seven. All in-progress and not-held artifacts removed. Business continuity split out and promoted to Held. Heading and lede rewritten.
  4. Your Data section. "You control attribution" callout and the documentation pull quote both removed. The pseudonymous-identifier point now survives only in the FAQ.
  5. Open editorial question. The Your Data lede still opens with a competitor comparison ("Most AI observability tools sit in the request path"). Flagged as sales voice, left in pending a decision.
MOCKUP — Trust Center v3.1 · Copy per "Revenium Trust Center — Page Copy v3" · Claim register in Appendix A of that document · Amber markers above are unresolved items