Security at Revtain
Revtain moves recovery attempts, not card data. Every control on this page describes how the system is actually built.
Card Data Never Enters Revtain
Revtain receives only opaque payment tokens issued by the client’s own payment gateway. No card number, expiry, or CVV ever transits or rests on Revtain servers, keeping the recovery flow outside PCI DSS cardholder-data scope. Read our privacy policy for data handling details.
Encryption and Access Control
All traffic is encrypted with TLS. Sensitive credentials are encrypted at rest with AES-256-GCM. API access uses scoped keys, and read-only keys are structurally incapable of initiating a charge.
Verifiable Money-Path Safety
Every webhook is HMAC-signed, every recovery attempt and delivery is durably logged, and the money-moving paths are enforced by an automated safety suite that must pass before any release ships. Report vulnerabilities to security@revtain.com.