Legal

Security

Last updated: July 2026

This page is a plain-language template to get you started and does not constitute legal advice — have it reviewed by counsel familiar with your jurisdiction before relying on it as a binding policy.

An overview of how we protect your data and your customers' conversations.

1. Data isolation

Every workspace's knowledge base, conversations, and leads are scoped by tenant at the database and vector-search layer — one customer's data is never used to answer another customer's questions.

2. Encryption

Data is encrypted in transit via TLS. Passwords are hashed, never stored in plain text. Authentication uses short-lived access tokens with refresh rotation.

3. Widget security

The public embeddable widget is scoped to a single, non-guessable widget key and runs inside an isolated Shadow DOM so it can't be affected by, or interfere with, the host page's scripts or styles.

4. Access control

Dashboard access is role-based (Owner, Admin, Sales, Support, Viewer) so team members only see what's relevant to their role.

5. Reporting a concern

If you believe you've found a security issue, please email support@revgenai.in with details — we take reports seriously and will respond promptly.