Trust & compliance
How SiteRevive protects workspace data, who processes it, and the agreements available to customers.
This is an evidence trail — not a certification.
SiteRevive maintains a SOC2-LITE posture: a documented, good-faith evidence trail (access logging, an encryption inventory, a current subprocessor list, and a fill-in DPA template). It is not a certified SOC 2 audit, and no certification or third-party attestation is claimed.
Evidence documents
- Encryption inventory
How data is protected at rest and in transit, plus secrets handling.
- Subprocessor list
The third-party services that process data on our behalf, and why.
- DPA template
A fill-in Data Processing Addendum template (not an executed agreement).
Access logging
Access logging is not implemented yet. SiteRevive ships the append-only table, the workspace-scoped query, and an owner-only viewer, but no part of the application writes to that table today, so the log is empty for every workspace. A workspace owner can see the viewer in-app at Trust & compliance → Access logs.