RevOS

Information Security Overview

Effective: 2026.02.01

Encryption

  • In transit: TLS 1.2+ enforced. HSTS, CAA, and DNSSEC enabled.
  • At rest: AES-256 on all databases, backups, and object storage.
  • Secrets: Managed in AWS Secrets Manager with per-environment KMS keys.
  • Identity & Access

  • MFA (TOTP) enforceable per Tenant; required for all RevOS staff.
  • RBAC with least-privilege default deny.
  • Session timeout configurable per Tenant (15 min – 24 h).
  • IP allow-listing available on Enterprise plans.
  • Network

  • Cloudflare WAF + DDoS L3/4/7 protection.
  • Private subnets for databases; no public DB endpoints.
  • Rate limits per API key + per route.
  • Operations

  • Immutable audit log of every admin action, 90-day hot retention +
  • 7-year archive.

  • Quarterly access reviews.
  • Annual third-party penetration test.
  • Weekly automated vulnerability scans.
  • SOC 2 Type I in progress · ISO 27001 in progress.
  • Business Continuity

  • RPO: 15 minutes · RTO: 4 hours.
  • Backups tested monthly.
  • Disaster-recovery region: AWS Mumbai (ap-south-1 secondary AZ).
  • Contact: founding@revos.co.in