Security and Trust

Built for organizations that cannot compromise on security

Reversa operates inside IBEX 35 and Fortune 500 companies, law firms, and public affairs consultancies handling confidential regulatory matters. The commitments below govern how the platform protects that work.

Independent penetration testing

Reversa has completed an independent penetration test of its platform. Every vulnerability identified during that assessment has been remediated, and the platform now passes without outstanding findings. The resulting report is available to clients and prospective clients under NDA.

ISO 27001 and SOC 2 in progress

Reversa is pursuing both ISO 27001 certification and a SOC 2 report. The information security management system underpinning both is implemented and operating, and the ISO 27001 internal audit stage is complete, with the external audit outstanding. Neither ISO 27001 certification nor a SOC 2 report has yet been granted; this page will be updated as each is completed.

Data protection and GDPR

Where Reversa processes personal data on a client’s behalf, it acts strictly as a data processor under the Data Processing Agreement that forms part of its Terms of Service. That agreement governs the purposes of processing, the confidentiality obligations binding authorised personnel, the use of sub-processors, retention periods, and the handling of any personal data breach.

Access control and operational security

Access to Reversa systems is restricted to authorised personnel, defined by role and reviewed periodically. Technical and organisational security measures are assessed on an ongoing basis, and Reversa’s security commitments are reviewed as its infrastructure evolves. The applicable measures are set out in full in the Data Processing Agreement.

Common questions

The questions security and procurement teams ask most often.

Is Reversa ISO 27001 certified or SOC 2 compliant?

Not yet; both are in progress. The information security management system underpinning them is implemented and operating, and the ISO 27001 internal audit is complete, with the external audit outstanding. Reversa does not claim either certification until it has been formally granted.

Has Reversa been penetration tested?

Yes. Reversa has completed an independent penetration test, and every vulnerability identified has been remediated. The report is available to clients and prospective clients under NDA.

Does Reversa sign a Data Processing Agreement?

Yes. A Data Processing Agreement forms part of Reversa’s Terms of Service and governs all processing of personal data carried out on a client’s behalf, including sub-processor obligations and breach notification.

Can Reversa complete a security questionnaire?

Yes. Reversa regularly completes vendor security questionnaires as part of enterprise procurement. Requests can be sent to info@reversa.ai.

Need our security documentation?

We share our penetration test report and complete vendor security questionnaires as part of procurement.

See also: Privacy Policy · Terms of Service