Effective: 2026.02.01
Encryption
In transit: TLS 1.2+ enforced. HSTS, CAA, and DNSSEC enabled.At rest: AES-256 on all databases, backups, and object storage.Secrets: Managed in AWS Secrets Manager with per-environment KMS keys.Identity & Access
MFA (TOTP) enforceable per Tenant; required for all RevOS staff.RBAC with least-privilege default deny.Session timeout configurable per Tenant (15 min – 24 h).IP allow-listing available on Enterprise plans.Network
Cloudflare WAF + DDoS L3/4/7 protection.Private subnets for databases; no public DB endpoints.Rate limits per API key + per route.Operations
Immutable audit log of every admin action, 90-day hot retention + 7-year archive.
Quarterly access reviews.Annual third-party penetration test.Weekly automated vulnerability scans.SOC 2 Type I in progress · ISO 27001 in progress.Business Continuity
RPO: 15 minutes · RTO: 4 hours.Backups tested monthly.Disaster-recovery region: AWS Mumbai (ap-south-1 secondary AZ).Contact: founding@revos.co.in