# Revup Security Practices

Revup is software for building, publishing, and measuring branded forms, sweepstakes, giveaways, contests, instant-win experiences, quizzes, surveys, referrals, coupons, and purchase promotions while collecting first-party data.

- Canonical HTML: https://revup.com/security/
- Full HTML page: [Open the canonical page](https://revup.com/security/)
- Last reviewed: 2026-07-24


## Current security practices

### Where is Revup hosted?

Revup's application and managed infrastructure are hosted with Northflank in the United States. Cloudflare provides global content delivery, network security, abuse prevention, and file storage services.

### How does Revup protect sensitive data?

Revup protects data in transit using HTTPS/TLS, and data stored in its primary infrastructure is encrypted at rest. Passwords are hashed using bcrypt, while sensitive integration credentials receive additional application-level encryption before storage.

### How does Revup protect public promotions from abuse?

Public and authentication flows use layered controls including request validation, rate limits, trusted-proxy-aware IP checks, duplicate and fraud checks, security blocklists, and Cloudflare Turnstile on supported high-risk actions.

### How are accounts and sessions protected?

Revup uses hashed passwords and session tokens, source-IP throttling, escalating account lockouts, optional customer two-factor authentication, required administrative two-factor authentication, account membership checks, and action-specific permissions.

### How are API credentials protected?

Revup shows an API key secret only when it is created or regenerated, stores only a hash for later verification, supports revocation, and applies account access checks and rate limits.

### How is the service monitored?

Revup sends application errors, performance signals, and operational logs to Better Stack. Worker-health checks monitor queue age, volume, stuck work, and delivery failures.

### What happens if a security incident affects Customer Data?

If Revup confirms that a security incident affected Customer Data, it will notify the affected Customer without undue delay and no later than 24 hours after confirmation, even if the investigation is continuing.

### Does Revup store payment-card numbers?

No. Stripe, Shopify, or another connected payment provider processes card information. Revup stores the billing, subscription, payment-status, and transaction identifiers needed to operate the configured service, but does not receive or store payment-card numbers.

### Does Revup claim a product-level security certification?

Revup does not currently publish a product-level SOC 2, ISO 27001, or PCI certification claim. Revup plans to pursue SOC 2 compliance.


## Related trust resources

- [Compliance resources](https://revup.com/compliance/)
- [Privacy Policy](https://revup.com/privacy/)
- [Subprocessor List](https://revup.com/subprocessors/)
