Storage and data location
Recovery points use Cloudflare R2 with AES-256 encryption at rest and TLS in transit. The production storage endpoint is restricted to R2's EU jurisdiction, and signed download links expire after five minutes.
Recovery points can contain personal data. These controls limit how ReviveDB accesses, stores, verifies and deletes it.
Recovery points use Cloudflare R2 with AES-256 encryption at rest and TLS in transit. The production storage endpoint is restricted to R2's EU jurisdiction, and signed download links expire after five minutes.
OAuth grants and fallback credentials use authenticated encryption with a separately supplied key. They are decrypted only by the backend operations that need them and are never returned through the API.
Production sessions use secure, HttpOnly cookies and can be revoked. Security events are recorded, and logs redact credentials, authorisation headers, email addresses and connection strings.
Every database backup is restored into isolated temporary Postgres and compared with the source inventory. Storage files and Edge Function bundles are hash-checked, scratch data is removed, and a mismatch fails the run.
If you are assessing ReviveDB for personal data, we can answer questions about access, retention, deletion, subprocessors or your security questionnaire.