Security at Revtain

Revtain moves recovery attempts, not card data. Every control on this page describes how the system is actually built.

Card Data Never Enters Revtain

Revtain receives only opaque payment tokens issued by the client’s own payment gateway. No card number, expiry, or CVV ever transits or rests on Revtain servers, keeping the recovery flow outside PCI DSS cardholder-data scope. Read our privacy policy for data handling details.

Encryption and Access Control

All traffic is encrypted with TLS. Sensitive credentials are encrypted at rest with AES-256-GCM. API access uses scoped keys, and read-only keys are structurally incapable of initiating a charge.

Verifiable Money-Path Safety

Every webhook is HMAC-signed, every recovery attempt and delivery is durably logged, and the money-moving paths are enforced by an automated safety suite that must pass before any release ships. Report vulnerabilities to security@revtain.com.