Built for the people who will ask for the proof.
Security is table stakes. What REVIEWIT adds is evidence and sovereignty: sealed, chained, retained and exported on your terms, in your region, by a platform whose own identity, secrets and operations are governed the same way.
A sealing authority, not a checksum.
Every closed occurrence and every audit segment is sealed by SEAL, a dedicated authority backed by a persistent vault. The application hosts cannot seal anything themselves, and cannot mint their own credentials.
- Vault-backed. Keys live in a hardware-grade vault unsealed with split shares. The authority derives, it never exposes.
- One identity per subscription. Each caller presents a certificate issued by the vault's own PKI, carrying its tenant. No tenant list, no restart at onboarding.
- Revocation and renewal. A signed revocation list read at every admission, a lifecycle job that renews before expiry and revokes archived subscriptions. The host does none of the three.
- Fails closed. A stale revocation list refuses in 503. A revoked caller refuses in 403. A broker that cannot read the list does not start.
- Issuer
- Vault PKI, not the host
- Renewal
- Lifecycle job, 30 days before expiry
- Old certificate
- Kept one day, then revoked
- Unknown subscription
- Neither renewed nor revoked
Chained per scope, sealed at closure, purged by segment.
The audit trail is not one endless log. It is a set of chains, one per scope, cut into segments that close and seal. A campaign occurrence is a scope. A subscription is a scope. Reading is by subscription, retention is by segment.
- Catalogue of codes. Every event has a governed code, a domain and a translation. Nothing free-form enters the chain.
- Segment, never row. Purge removes sealed segments whose retention has elapsed. It never deletes a line from a live chain.
- A scope declares itself. New modules bring their own scope and their own retention line. Deletion requests, legal holds and every governed object have one.
- Certification dossier. For administrators, the evidence of an occurrence assembled and readable. Export and signature belong to the sealed chain, not to a PDF.
The auditor observes, proves and exports. Never pilots.
An audit asks you to demonstrate design, execution with evidence, and completeness of your reviews. That is a need to read and to export, never to act. REVIEWIT gives auditors a role of their own in the Workspace Manager, with a permanent read-only banner, an expiry, and a home built around the three numbers they will ask for.
- A role, not a mode. Auditor is one of the four workspace roles, held by a person or a group, twelve months at most. The banner states the role and its expiry on every page.
- Audit posture. Coverage, sealed attestations, the state of the trail in four facts, the measured causes of what is not covered, the latest proofs. Every figure leads to its material.
- Audit trail reader. The chain by scope, with an integrity verdict on the whole subscription and rows bounded to the workspace. Campaign-scoped reading too.
- Audit dossier. Pick campaigns into a basket and export a canonical dossier with a SHA-256 digest, the sign-off packages embedded under a manifest, the auditor's own perimeter snapshot, and a conflict-of-interest mention if the same person also holds Manager.
- Verify evidence. Drop a sign-off package and the authority's published keyring: the verdict is recomputed every time, never read from storage, and the verification is written to the trail before it is shown. Open to every role.
- Denied by design. No decision, no campaign creation or closure, no INSIGHTS, no alerts. The absence of buttons reads as a status, not a bug.
Built for sovereign requirements. Starting in Europe.
Ministries, agencies, local authorities, operators of essential services and regulated industries face the same demand, whatever their jurisdiction: keep the data, the keys and the decision at home, and prove it. REVIEWIT was designed for that demand from the first line, not adapted to it afterwards. It opens in Europe first, and the same architecture serves any region.
A region you choose, and nothing leaves it
Authentication, sealing authority, secrets, mail, audit trail: every service runs in the region of your subscription. The control plane holds metadata only and never reads down into a region. The metering channel cannot even carry your data.
A dedicated silo when you need one
Shared cell for most, a dedicated account for large groups: one silo, one customer, never two. Migration between them is a move, never a copy. On your premises when the regulator says so.
One key per tenant, no platform secret
Each subscription seals with its own key in a vault the application hosts cannot open. One OAuth application per customer, so there is no platform-wide secret to steal. Bring your own key is on the roadmap, documented down to who bears the loss of a key.
The editor does not see your data
REVIEWIT staff have no implicit access to customer data, ever. Support access is explicit, bounded in time, consented by you and written to your own audit trail. The same rule that keeps administrators from deciding keeps the editor from reading.
Proof that stands without us
The trail is chained and sealed. The verifier is the same in the console and on the command line, and the authority's keyring is published at a well-known address, anchored on its root key. An auditor can check a package with no account and no call to us.
Humans decide, always
No system signature, no delegated signer, no decision action in the assistant's contract. In front of the AI Act or a works council, the answer is structural, not a policy. Sovereignty over the decision is the one nobody else offers.
Your jurisdiction, by construction
A region per subscription, opened where your law applies, so your data stays under it and out of reach of extraterritorial disclosure. European regions first, others on demand. On-premise deployment for isolated or classified environments.
Evidence for your frameworks
Periodic certification of access, ownership and resource compliance with sealed proof is what NIS2, DORA, the AI Act and their equivalents elsewhere ask a public body or an operator of essential services to demonstrate. Human oversight of the assistant is structural, not a policy.
Leave with everything, verify without us
Evidence, audit trail and configuration are exportable in open formats, the verifier and its keyring are published, and the on-premise edition runs the same platform. No lock-in on the proof, no dependency on the publisher to read it.
SEAL seals. BEACON broadcasts.
Your security operations should see what your reviewers did, in the tool they already watch. BEACON streams the audit trail to your SIEM as it is written, in one open format, with a manifest per batch that your team can verify without asking us.
- The trail is the outbox. No second queue. BEACON reads the chain by sequence and keeps one checkpoint per destination. At-least-once, with an event id for de-duplication.
- One format on the wire. OCSF envelopes with the canonical event kept intact, so the hash recomputes on the receiver. Splunk, Sentinel, Elastic and Chronicle mappings live in the connectors.
- No dead-letter queue. A destination that fails pauses and raises an alert. An event is never skipped: a hole would break the chain.
- Egress is a security boundary. HTTPS only, DNS pinning, no loopback, link-local or metadata addresses, a dedicated egress proxy, no redirects. Cross-region destinations need a formal acknowledgement.
- Verifiable batches. Each batch carries a deterministic id and a manifest; the verifier checks continuity and integrity of what you received.
Automate everything around the decision. Never the decision.
A REST API for your tooling: read campaigns and their configuration, follow reviews and their effective decision, pull the audit trail by cursor, generate signed evidence on demand, track deletion requests, browse the resource catalogue. One thing is impossible by design: posting a review decision.
- OAuth2 client credentials. Machine clients with a secret or, at the perimeter, a certificate. Tokens carry the subscription; it is never a parameter.
- Scopes by integration profile. SIEM, BI and reporting, ITSM, IGA, evidence archiving: presets that bundle the right scopes, with the admin scope never pre-ticked.
- Managed from the Subscription Manager. Create a client in four steps, reveal the secret once, rotate, disable, revoke. Every act on a client is in the audit trail. A revoked client dies within five minutes, tokens included.
- Frozen contract. OpenAPI v1 is pinned by a contract test. Cursor pagination everywhere, opaque ids, normalised statuses.
- Webhooks next. Campaign events, including a dedicated signed-off event, pushed to your systems from the same outbox.
Defence in depth, governed like the rest.
TrustGate
An identity broker in front of every console. Entra ID, Google and generic OIDC providers. MFA step-up on administrative surfaces with authentication freshness enforced, and a setup guide per provider.
Secrets in a store, never in files
No secret lives in configuration. Customer keys, the assistant's call secret and the platform's own identities are held in the vault and rotated by jobs, not by hand.
BYOK and encryption
Bring your own key for your subscription's data. Encryption at rest and in transit, tenant isolation by design, and a regional foundation so your data stays in your region.
BEACON
The audit trail streamed to your SIEM in OCSF, one checkpoint per destination, verifiable batches, egress as a security boundary. How BEACON broadcasts →
Public API
Read campaigns, reviews, evidence, audit, deletions and resources with scoped machine clients. No script can decide. What the API exposes →
Operational health
Every background job posts a summary. A job that stays silent is a finding, not a comfort. Alerts on jobs and services are visible to your subscription.
Retention you can sign, deletion you can track.
Retention module
Every data category is declared with a retention period and a purge behaviour, matching the DPA clause in your contract. What is purged is purged by segment, never by row.
Legal holds
A hold suspends purge for a subscription, a campaign or a category, with a reason and an owner. Evidence under hold outlives its retention until the hold is lifted.
Deletion requests
A reviewer can ask for a resource to be deleted. The request is tracked from filing to execution or refusal, with the trace of who processed it and why.
Aligned with what your auditors expect.
SOC 2 Type II
Independently audited against the trust service criteria: change control, logging, access, availability.
ISO/IEC 27001
Certified information security management system, covering the platform, the vault and the sealing authority.
GDPR
Privacy-aware collection, normalised at ingestion, declared retention, DPA clause, deletion requests with an execution model.
Pentest-driven
Regular penetration testing and a secure development lifecycle, with static analysis baselines tracked on risk, not on totals.
AI Act
Human oversight with the capacity to intervene, automatic logs retained, demonstrability: RITA's ledger is that demonstration.
Managed in your region, or on your premises.
The same platform, the same evidence model, the same reviewer experience. Choose where it runs.
Managed service
Operated by REVIEWIT on a regional foundation. One cell per region, your subscription's database in that cell or in a dedicated silo. Authentication and sealing authorities per region. Continuous updates, no infrastructure to run.
- Fastest time to first campaign
- Regional data residency
- Dormant and running postures to control cost
On-premise
Hosted within your own infrastructure for strict sovereignty, regulatory or network isolation requirements. The same consoles, jobs, vault and sealing authority, deployed and updated under your control.
- Full data sovereignty
- Your network boundaries
- Designed for regulated environments
Request the security dossier.
Architecture, sealing authority, retention declaration, DPA clause, deployment options. We will walk your security team through it.
