DRAFT — This document is prepared for internal review and is not legal advice. It must be reviewed by a licensed attorney before publication. Effective date (pending review): December 21, 2026.

Security at Revundo (formerly Verifund) — DRAFT (requires review before publishing)

How we protect merchant and shopper data today. Last updated: December 21, 2026

Architecture

Revundo runs on Vercel (hosting) and Supabase (Postgres database), with billing through Stripe. Data is encrypted with TLS in transit and encrypted at rest by our hosting providers.

Data minimization

Shopper identifiers are hashed before they leave the merchant's store. Return photos and reasons are stored only as long as needed to resolve the return. Cross-merchant Trust Network signals are derived from de-identified data only — raw shopper identities are never shared between merchants, and the Trust Network is not enabled for a merchant until a Data Processing Addendum is signed.

Access control

Least-privilege access: only the founder can access production data, and only when needed for support or debugging. No production customer data is used in demos or testing.

What we don't do yet

We are a small team and do not yet hold SOC 2 or ISO 27001 certification. Independent certification is on our roadmap as we grow.

Responsible disclosure

Found a vulnerability? Email hello@revundo.com with details. We will acknowledge within 2 business days and keep you updated until it is resolved. Please do not access other merchants' data or disrupt the service while researching.


DRAFT — prepared for internal review. Must be reviewed before publishing. Security practices are described as currently implemented; do not overstate them in sales conversations.