DISCOVER · REVIEW · REMEDIATE
Trust & Evidence

Built for the people who will ask for the proof.

Security is table stakes. What REVIEWIT adds is evidence and sovereignty: sealed, chained, retained and exported on your terms, in your region, by a platform whose own identity, secrets and operations are governed the same way.

SEAL sealing authorityAudit trail per scopeBEACON to your SIEMPublic APIBYOKEncryption at rest & in transitGDPR alignedSOC 2 readyPentest-drivenOn-premise availableSovereign by design
SEAL

A sealing authority, not a checksum.

Every closed occurrence and every audit segment is sealed by SEAL, a dedicated authority backed by a persistent vault. The application hosts cannot seal anything themselves, and cannot mint their own credentials.

  • Vault-backed. Keys live in a hardware-grade vault unsealed with split shares. The authority derives, it never exposes.
  • One identity per subscription. Each caller presents a certificate issued by the vault's own PKI, carrying its tenant. No tenant list, no restart at onboarding.
  • Revocation and renewal. A signed revocation list read at every admission, a lifecycle job that renews before expiry and revokes archived subscriptions. The host does none of the three.
  • Fails closed. A stale revocation list refuses in 503. A revoked caller refuses in 403. A broker that cannot read the list does not start.
SEAL Subscription caller · admission
Caller certificateCN=seal-caller, OU=<pseudonym>
Revocation listSigned, re-read every 5 min
AdmittedSeal issued for segment #47
Issuer
Vault PKI, not the host
Renewal
Lifecycle job, 30 days before expiry
Old certificate
Kept one day, then revoked
Unknown subscription
Neither renewed nor revoked
Gate G1 ratifiedFour invariants, each demonstrated by its own issuer
Audit trail

Chained per scope, sealed at closure, purged by segment.

The audit trail is not one endless log. It is a set of chains, one per scope, cut into segments that close and seal. A campaign occurrence is a scope. A subscription is a scope. Reading is by subscription, retention is by segment.

  • Catalogue of codes. Every event has a governed code, a domain and a translation. Nothing free-form enters the chain.
  • Segment, never row. Purge removes sealed segments whose retention has elapsed. It never deletes a line from a live chain.
  • A scope declares itself. New modules bring their own scope and their own retention line. Deletion requests, legal holds and every governed object have one.
  • Certification dossier. For administrators, the evidence of an occurrence assembled and readable. Export and signature belong to the sealed chain, not to a PDF.
Audit trail Scope: campaign occurrence 9000003
CAMPAIGN.ARMEDPerimeter frozen: 4 118 objects
Segment 102 Sep 09:00Sealed
REVIEW.DECISION × 3 902Named reviewers, comments, evidence
Segment 202–10 SepSealed
SIGNOFF.SIGNEDWorkspace manager, batch of 3 902
Segment 311 Sep 17:12Sealed
CAMPAIGN.CLOSEDOccurrence closed, results relieved
Segment 311 Sep 17:15Sealed
Read by subscriptionAuditor: read-only
The auditor surface

The auditor observes, proves and exports. Never pilots.

An audit asks you to demonstrate design, execution with evidence, and completeness of your reviews. That is a need to read and to export, never to act. REVIEWIT gives auditors a role of their own in the Workspace Manager, with a permanent read-only banner, an expiry, and a home built around the three numbers they will ask for.

Workspace Manager · Auditor
Read-only audit posture, with the state of the trail
Read-only audit posture, with the state of the trail
  • A role, not a mode. Auditor is one of the four workspace roles, held by a person or a group, twelve months at most. The banner states the role and its expiry on every page.
  • Audit posture. Coverage, sealed attestations, the state of the trail in four facts, the measured causes of what is not covered, the latest proofs. Every figure leads to its material.
  • Audit trail reader. The chain by scope, with an integrity verdict on the whole subscription and rows bounded to the workspace. Campaign-scoped reading too.
  • Audit dossier. Pick campaigns into a basket and export a canonical dossier with a SHA-256 digest, the sign-off packages embedded under a manifest, the auditor's own perimeter snapshot, and a conflict-of-interest mention if the same person also holds Manager.
  • Verify evidence. Drop a sign-off package and the authority's published keyring: the verdict is recomputed every time, never read from storage, and the verification is written to the trail before it is shown. Open to every role.
  • Denied by design. No decision, no campaign creation or closure, no INSIGHTS, no alerts. The absence of buttons reads as a status, not a bug.
Verification does not require our servers. The offline verification specification is published, and the sealing authority's keyring is served at a well-known address, anchored on its root key so rotations never invalidate an old proof. The same verifier runs in the console and on the command line, byte for byte.
Sovereignty · Public sector & regulated industries

Built for sovereign requirements. Starting in Europe.

Ministries, agencies, local authorities, operators of essential services and regulated industries face the same demand, whatever their jurisdiction: keep the data, the keys and the decision at home, and prove it. REVIEWIT was designed for that demand from the first line, not adapted to it afterwards. It opens in Europe first, and the same architecture serves any region.

RESIDENCE

A region you choose, and nothing leaves it

Authentication, sealing authority, secrets, mail, audit trail: every service runs in the region of your subscription. The control plane holds metadata only and never reads down into a region. The metering channel cannot even carry your data.

ISOLATION

A dedicated silo when you need one

Shared cell for most, a dedicated account for large groups: one silo, one customer, never two. Migration between them is a move, never a copy. On your premises when the regulator says so.

KEYS

One key per tenant, no platform secret

Each subscription seals with its own key in a vault the application hosts cannot open. One OAuth application per customer, so there is no platform-wide secret to steal. Bring your own key is on the roadmap, documented down to who bears the loss of a key.

NO STANDING ACCESS

The editor does not see your data

REVIEWIT staff have no implicit access to customer data, ever. Support access is explicit, bounded in time, consented by you and written to your own audit trail. The same rule that keeps administrators from deciding keeps the editor from reading.

VERIFIABLE

Proof that stands without us

The trail is chained and sealed. The verifier is the same in the console and on the command line, and the authority's keyring is published at a well-known address, anchored on its root key. An auditor can check a package with no account and no call to us.

DECISION

Humans decide, always

No system signature, no delegated signer, no decision action in the assistant's contract. In front of the AI Act or a works council, the answer is structural, not a policy. Sovereignty over the decision is the one nobody else offers.

JURISDICTION

Your jurisdiction, by construction

A region per subscription, opened where your law applies, so your data stays under it and out of reach of extraterritorial disclosure. European regions first, others on demand. On-premise deployment for isolated or classified environments.

FRAMEWORKS

Evidence for your frameworks

Periodic certification of access, ownership and resource compliance with sealed proof is what NIS2, DORA, the AI Act and their equivalents elsewhere ask a public body or an operator of essential services to demonstrate. Human oversight of the assistant is structural, not a policy.

REVERSIBILITY

Leave with everything, verify without us

Evidence, audit trail and configuration are exportable in open formats, the verifier and its keyring are published, and the on-premise edition runs the same platform. No lock-in on the proof, no dependency on the publisher to read it.

Where we start. France, Switzerland and Benelux first, other European regions opened on demand. We work with the procurement, security and legal teams of public bodies and regulated organisations on the questionnaire, the DPA and the hosting attestation, in French or in English.
BEACON Unlimited

SEAL seals. BEACON broadcasts.

Your security operations should see what your reviewers did, in the tool they already watch. BEACON streams the audit trail to your SIEM as it is written, in one open format, with a manifest per batch that your team can verify without asking us.

  • The trail is the outbox. No second queue. BEACON reads the chain by sequence and keeps one checkpoint per destination. At-least-once, with an event id for de-duplication.
  • One format on the wire. OCSF envelopes with the canonical event kept intact, so the hash recomputes on the receiver. Splunk, Sentinel, Elastic and Chronicle mappings live in the connectors.
  • No dead-letter queue. A destination that fails pauses and raises an alert. An event is never skipped: a hole would break the chain.
  • Egress is a security boundary. HTTPS only, DNS pinning, no loopback, link-local or metadata addresses, a dedicated egress proxy, no redirects. Cross-region destinations need a formal acknowledgement.
  • Verifiable batches. Each batch carries a deterministic id and a manifest; the verifier checks continuity and integrity of what you received.
BEACON Destinations · France · Corporate
Splunk · SOC ParisHTTP egress · HEC profile · eu-west-3
Checkpoint 184 220Lag 41 sActive
Sentinel · Group SOCHTTP egress · eu-west-1 · cross-region acknowledged
Checkpoint 184 220Lag 58 sActive
Evidence archiveS3 · manifest per batch · eu-west-3
Checkpoint 183 990Paused, alert raisedPaused
Batch 5f3a…184 001 → 184 220
Manifestexit hash, count, integrity version
Acknowledgedcheckpoint advanced in one transaction
OCSF 1.5At-least-oncePull available in every edition; push and content packs with Unlimited
Public API Unlimited

Automate everything around the decision. Never the decision.

A REST API for your tooling: read campaigns and their configuration, follow reviews and their effective decision, pull the audit trail by cursor, generate signed evidence on demand, track deletion requests, browse the resource catalogue. One thing is impossible by design: posting a review decision.

  • OAuth2 client credentials. Machine clients with a secret or, at the perimeter, a certificate. Tokens carry the subscription; it is never a parameter.
  • Scopes by integration profile. SIEM, BI and reporting, ITSM, IGA, evidence archiving: presets that bundle the right scopes, with the admin scope never pre-ticked.
  • Managed from the Subscription Manager. Create a client in four steps, reveal the secret once, rotate, disable, revoke. Every act on a client is in the audit trail. A revoked client dies within five minutes, tokens included.
  • Frozen contract. OpenAPI v1 is pinned by a contract test. Cursor pagination everywhere, opaque ids, normalised statuses.
  • Webhooks next. Campaign events, including a dedicated signed-off event, pushed to your systems from the same outbox.
API Access Subscription Manager · 3 clients
Splunk SIEM exportrvw_199d… · certificate · audit.read, evidence.read
SIEM preset12 480 calls / 30 dEnabled
Power BI governancervw_7c02… · secret · campaigns.read, reviews.read
BI preset3 910 calls / 30 dEnabled
ServiceNow ticketsrvw_e41a… · secret · deletions.read
ITSM presetRevoked 2 SepRevoked
6Read domains in v1
0Ways to post a decision
5 minRevocation to dead token
OpenAPI v1, pinnedCursor paginationEvery act on a client is audited
Security foundations

Defence in depth, governed like the rest.

TrustGate

An identity broker in front of every console. Entra ID, Google and generic OIDC providers. MFA step-up on administrative surfaces with authentication freshness enforced, and a setup guide per provider.

Secrets in a store, never in files

No secret lives in configuration. Customer keys, the assistant's call secret and the platform's own identities are held in the vault and rotated by jobs, not by hand.

BYOK and encryption

Bring your own key for your subscription's data. Encryption at rest and in transit, tenant isolation by design, and a regional foundation so your data stays in your region.

BEACON

The audit trail streamed to your SIEM in OCSF, one checkpoint per destination, verifiable batches, egress as a security boundary. How BEACON broadcasts →

Public API

Read campaigns, reviews, evidence, audit, deletions and resources with scoped machine clients. No script can decide. What the API exposes →

Operational health

Every background job posts a summary. A job that stays silent is a finding, not a comfort. Alerts on jobs and services are visible to your subscription.

Data governance

Retention you can sign, deletion you can track.

Retention module

Every data category is declared with a retention period and a purge behaviour, matching the DPA clause in your contract. What is purged is purged by segment, never by row.

Legal holds

A hold suspends purge for a subscription, a campaign or a category, with a reason and an owner. Evidence under hold outlives its retention until the hold is lifted.

Deletion requests

A reviewer can ask for a resource to be deleted. The request is tracked from filing to execution or refusal, with the trace of who processed it and why.

Compliance & assurance

Aligned with what your auditors expect.

SOC 2 Type II

Independently audited against the trust service criteria: change control, logging, access, availability.

ISO/IEC 27001

Certified information security management system, covering the platform, the vault and the sealing authority.

GDPR

Privacy-aware collection, normalised at ingestion, declared retention, DPA clause, deletion requests with an execution model.

Pentest-driven

Regular penetration testing and a secure development lifecycle, with static analysis baselines tracked on risk, not on totals.

AI Act

Human oversight with the capacity to intervene, automatic logs retained, demonstrability: RITA's ledger is that demonstration.

Deployment

Managed in your region, or on your premises.

The same platform, the same evidence model, the same reviewer experience. Choose where it runs.

Managed service

Operated by REVIEWIT on a regional foundation. One cell per region, your subscription's database in that cell or in a dedicated silo. Authentication and sealing authorities per region. Continuous updates, no infrastructure to run.

  • Fastest time to first campaign
  • Regional data residency
  • Dormant and running postures to control cost

On-premise

Hosted within your own infrastructure for strict sovereignty, regulatory or network isolation requirements. The same consoles, jobs, vault and sealing authority, deployed and updated under your control.

  • Full data sovereignty
  • Your network boundaries
  • Designed for regulated environments

Request the security dossier.

Architecture, sealing authority, retention declaration, DPA clause, deployment options. We will walk your security team through it.