Security practices

Revup Security

Straightforward answers about the safeguards used across Revup accounts, Promotions, infrastructure, and operations.

Last reviewed:

Security FAQ

Common security questions

These answers describe Revup's current application practices. They are not a certification or independent audit report.

Infrastructure and data protection

Where is Revup hosted?

Revup's application and managed infrastructure are hosted with Northflank in the United States. Cloudflare provides global content delivery, network security, abuse prevention, and file storage services. Our Subprocessor List identifies the core and feature-dependent providers that support the service.

How does Revup protect sensitive data?

Revup protects data in transit using HTTPS/TLS, and data stored in its primary infrastructure is encrypted at rest. Passwords are hashed using bcrypt, while sensitive integration credentials receive additional application-level encryption before storage.

How does Revup protect public Promotions from abuse?

Public and authentication flows use layered controls such as request validation, rate limits, trusted-proxy-aware IP checks, duplicate and fraud checks, security blocklists, and Cloudflare Turnstile on supported high-risk actions. The exact checks depend on the Promotion feature and action being used.

Accounts and application access

How are passwords and sessions protected?

Revup hashes passwords with bcrypt and does not store plaintext passwords. Sign-in is protected by source-IP throttling and escalating account lockouts. Authentication session tokens are randomly generated, stored as hashes, and revoked after a successful password reset.

Does Revup support two-factor authentication?

Yes. Customer users can enable time-based one-time-password two-factor authentication. Revup requires an active two-factor-authenticated session for administrative access.

How is access to Customer data controlled?

Authenticated application routes enforce account membership and action-specific permissions. Customers can assign roles that separate access to account settings, team management, billing, integrations, Promotions, Participants, winners, reporting, and other account functions. Customers remain responsible for granting only the access their users need.

How are API credentials protected?

Revup shows an API key's secret only when it is created, stores only a hash for later verification, supports revocation, and applies account-level access checks and rate limits to API activity.

Operations and third parties

How is the service monitored?

Revup sends application errors, performance signals, and operational logs to Better Stack. Worker-health checks also monitor queue age, volume, stuck work, and delivery failures so operational problems can be investigated.

What happens if a security incident affects Customer Data?

If Revup confirms that a security incident affected Customer Data, we will notify the affected Customer without undue delay and no later than 24 hours after confirmation, even if the investigation is continuing. Additional responsibilities are described in the Security section of our Privacy Policy.

Does Revup store payment-card numbers?

No. Stripe, Shopify, or another connected payment provider processes payment-card information under its own policies. Revup stores the billing, subscription, payment-status, and transaction identifiers needed to operate the configured service, but it does not receive or store payment-card numbers.

Does Revup claim a product-level security certification?

Revup does not currently publish a product-level SOC 2, ISO 27001, or PCI certification claim. Some infrastructure and payment providers maintain their own certifications, but a provider's certification is not represented as a certification of Revup itself.

Ready to launch your
first promotion?

Free trial No credit card required Cancel anytime