Security, Ownership & Control

If A Platform Can See The Whole Business, The Owner Needs To Know Exactly What It Can Touch. And How To Stop It.

RevForge connects customers, jobs, calls, crews, prices, margin, collections, cash, and business value. Trust cannot be a lock icon or a vague promise. The owner needs explicit data ownership, isolation, authority boundaries, revocable access, and a traceable record of every automated action.

Owner Security ContractCurrent Posture
Data ownershipYour business data remains yours and stays exportable.
Owner controlled
Business isolationEach business is isolated from every other business.
Active
EncryptionData is encrypted in transit and at rest.
Active
Action authorityThe owner defines what Rev can watch, prepare, or execute.
Owner configured
AuditabilityAutomated actions are written to an append-only audit trail.
Logged
SOC 2 certificationThe platform is built to SOC 2 standards; certification is not complete.
In progress
The Owner’s RightKnow what Rev can see, what it can do, who approved it, and how to stop it.
The Control Contract

Security Is The Contract Behind Every Connection.

The platform can only improve the whole business if the owner can trust the boundaries around the whole business. These controls define ownership, access, action, isolation, and accountability.

Standards

Built to SOC 2 standards without pretending the certification is finished

Access controls, audit logging, change management, and production security practices are designed around SOC 2 standards. RevForge is not certified yet. Certification is in progress, and the current status can be reviewed directly with the team.

Current state: standards implemented · certification in progress
Ownership

Your operating history does not become someone else’s product

Your customers, jobs, prices, crews, calls, margin, cash, and outcomes belong to your business. RevForge does not sell that data and does not hand raw business data to an outside party to train on. You can export it or close the account.

Owner data · exportable · never sold
Protection

Sensitive evidence is protected in transit, at rest, and in use

Data is encrypted in transit and at rest. Access follows least-privilege principles and is logged. Automated actions are recorded in an append-only audit trail the business can review.

Encrypted · least privilege · logged
Isolation

Another contractor’s business never becomes your raw comparison set

Every business is isolated from every other. Raw tenant data is not pooled across shops. A business can choose to participate in anonymized benchmarks, but those benchmarks do not expose another contractor’s underlying data.

Per-business isolation · benchmark opt-in
Authority

The platform never gets more authority than the owner gives it

Rev can watch, recommend, prepare, or execute by decision and domain. Higher-impact moves can require approval. Authority can be reduced at any time, and the owner can use the master switch to stop automated action.

Decision-level authority · approval gates · master switch
Connections

Outside access is scoped, revocable, verified, and consent-gated

When RevForge connects to an outside service, it requests only the access needed for that job. Access is scoped and revocable. Inbound connections are signature-verified and gated by consent.

Minimum scope · revocable access · verified inbound traffic
The Non-Negotiables

What RevForge Will Never Do With The Business You Built.

Security is also defined by the lines a platform refuses to cross. These promises are not hidden in a settings page or left for the owner to infer.

×
Sell your business data

Customer, job, financial, operating, and outcome data does not become a resale product.

×
Give raw business data to an outside party for training

The contractor’s private operating history is not handed to an outside party to train on.

×
Pool one shop’s raw numbers with another

Businesses remain isolated. Any anonymized benchmark participation is optional and does not expose raw tenant data.

×
Act beyond the authority the owner configured

Every action is limited by domain, decision, confidence, price, margin, spend, and other owner-defined rules.

×
Hide the current certification status

RevForge is built to SOC 2 standards, but it is not certified yet. Certification is in progress.

×
Trap the history that belongs to the contractor

The owner can export the business data or close the account; the operating history goes with the business.

Authority Before Automation

Every Action Has A Boundary And A Trail.

RevForge does not treat connected access as unlimited permission. Evidence is scoped, owner authority is checked, outside access is minimized, and automated action remains reviewable after it runs.

Illustrative Controlled ActionAuthority Check Active
01Evidence is gathered

Only the signals and records needed to understand the decision are brought into context.

Source stays attached
02Owner authority is checked

The decision is matched against the configured domain, action level, limits, confidence, and approval rules.

Boundary checked before action
03The minimum required access is used

Where an outside service is needed, access stays scoped to the work and can be revoked.

Scoped and revocable
04The action and result are recorded

Automated action is written to the append-only audit trail so the owner can see what moved and why.

Action remains traceable
Owner VisibilityThe evidence, authority decision, connection scope, action, and result stay traceable.
Bring The Real Security Questions

Do Not Accept “Enterprise-Grade” As The Answer.

Building a security review, evaluating access, or checking a specific workflow? Ask for the current SOC 2 progress, data-flow details, authority model, isolation approach, or connection scope. RevForge will answer with the current state. It will not claim a certification or control the company does not yet have.

hello@revforgeos.com