Workspace isolation
Production data is scoped to the customer workspace and protected with database Row Level Security and role-based permissions.
Security & data practices
RevoCapture’s production architecture is designed around tenant isolation, least privilege, customer-owned communications providers, suppression controls, and auditable workflow state.
Production data is scoped to the customer workspace and protected with database Row Level Security and role-based permissions.
Phone, SMS, and carrier accounts stay under the customer’s ownership wherever practical. RevoCapture does not need to routinely front telecom charges.
Opt-outs and suppressions are designed to override active workflows. Unknown contactability is not treated as automatic permission to send.
RevoCapture does not claim SOC 2, ISO 27001, HIPAA, PCI DSS service-provider certification, legal compliance certification, or any other certification that has not actually been obtained. Payment card data is intended to be handled by Stripe rather than stored by RevoCapture.
Security depends on correct deployment and account configuration. Live cross-tenant, browser, payment, and provider tests are required before production launch.
Customers retain control of their business data and external provider accounts. RevoCapture includes export and workspace-deletion paths so a customer is not intentionally trapped in the platform.