What Reveal can see, and what it can't.
Reveal is the financial evidence and context layer between the systems where financial activity happens and the systems where accounting work gets done. This page is written for three readers: a client deciding whether to connect, a practice owner doing due diligence, and an IT or compliance reviewer. Each section starts in plain English. Technical detail sits underneath.
Defined access to the sources a client approves
Email (Gmail, Outlook / Microsoft 365, Yahoo Mail, AOL Mail, IMAP) with read-only mailbox access, supplier portals, WhatsApp Business, OneDrive and SharePoint, and uploaded documents. Each source is approved explicitly and can be disconnected at any time.
- Reveal can't send, modify or delete email.
- Only sources the client approves are connected.
- The practice never receives a general mailbox browser.
Overview
Reveal connects only to sources a client approves, retrieves financial evidence from them, and gives the practice that evidence with its context. Never the underlying mailbox, supplier account or drive.
Email access — Gmail, Outlook / Microsoft 365, Yahoo Mail, AOL Mail and IMAP
Reveal connects to email to retrieve financial evidence. It can't send, modify or delete messages. Relevant evidence is surfaced into Reveal; your accountant is not given a general inbox browser.
Supplier portal access
Supplier portals don't offer read-only connections the way email providers do. To retrieve invoices, Reveal signs in to the supplier account with the client's approval. That login is protected as carefully as a mailbox permission, and the practice never gets a browser into the account.
- Credentials are never displayed through Reveal
- A rejected supplier password is deleted immediately
- The stored supplier credential is deleted on disconnect
- If the supplier asks for a one-time code, Reveal asks you for it. It's used for that sign-in only and isn't kept
WhatsApp Business
Reveal connects to a WhatsApp Business account through the WhatsApp Business Platform. It never logs in to personal WhatsApp. The business connects explicitly, and receipts or invoices sent to that business number can feed Reveal as evidence.
OneDrive
A Microsoft Graph connection with a read-only, least-privilege approach. Connect the locations where financial evidence lives; Reveal retrieves supported evidence from those approved locations. It doesn't need edit or delete rights.
Uploads
Documents added directly by the client or the practice join the same financial story, carrying who uploaded them and when.
Access & visibility
Source access is not practice visibility. Reveal may need enough technical access to a connected system to retrieve evidence. That doesn't give the accounting practice access to that system.
Reveal personnel access
Customer information may be accessed by authorised Reveal personnel where necessary to operate, support or secure the service. Access uses individual identities, multi-factor authentication and role-based controls, and sensitive access is recorded.
- A separate identity for every authorised staff member
- Multi-factor authentication enforced
- Role-based access controls
- Every sensitive customer-data read logged against the individual
- Detailed technical controls are in Reveal's security pack, available on request from hello@revealos.com.
Credential protection
Connection credentials and access tokens are encrypted before storage, decrypted only when needed to connect to an approved source, and never displayed back through the product.
- Credentials are held separately from evidence and product data
- Stored credentials are deleted when a source is disconnected
- Detailed technical controls are in Reveal's security pack, available on request from hello@revealos.com.
Encryption
Connections between Reveal, users and connected providers use encrypted transport such as TLS. Credentials and tokens are encrypted with AES-256-GCM before storage.
Authentication & privileged access
Practice users sign in with a passwordless magic link. Reveal staff and infrastructure accounts use multi-factor authentication, and production access follows least privilege.
Practice isolation
Information is scoped to the practice and client workspace it belongs to: clients, connections, evidence and ledger links. Internal privileged access is controlled separately.
FROM
Data lifecycle
Follow a piece of evidence from connection to deletion. Choose a stage to see what's involved.
Retention & deletion
Disconnecting and deleting are different things, so here they are side by side.
- Disconnecting stops future retrieval and deletes the stored credential or token. Evidence already retrieved remains available to the accounting practice until the practice instructs Reveal to delete it or the applicable retention period expires.
- If you created an IMAP app password, revoke it with your email provider too.
Auditability
Important access and actions leave a trace.
- Source connected or disconnected
- Evidence retrieved
- Document viewed or downloaded
- Matching and association decisions
- Ledger actions
- Privileged and administrative access, attributed to the individual
AI & model processing
Reveal is AI-native, and we explain what AI does and where your information goes. It reads documents, extracts data, understands evidence, associates and matches it, assists supplier-portal navigation, explains its reasoning, powers Ask Reveal and keeps working in the background.
- Reveal does not train cross-customer Reveal models on client information unless separately authorised.
- External model providers' retention and training settings are disclosed separately, below.
Subprocessors
The companies that process information on Reveal's behalf. Reveal assesses each provider before customer data is routed through it. The full register, with what each receives, retention and transfer safeguards, is in the Data Processing Agreement and available on request.
- International transfers are covered by Standard Contractual Clauses with the UK Addendum, or equivalent safeguards
- Not treated as subprocessors: Google, Microsoft, Yahoo/AOL and connected accounting systems, when they are the source or destination the customer chose. Stripe acts separately for Reveal billing.
Security operations
What's in place to run Reveal securely. Reveal doesn't claim certifications it hasn't confirmed. Report a security concern to the privacy and compliance contact, hello@revealos.com.
- Detailed technical controls are in Reveal's security pack, available on request from hello@revealos.com.
UK GDPR
The accounting practice generally acts as Controller for its client processing. Reveal acts as Processor when processing client information on the practice's instructions, and separately as Controller for its own account and billing information. This is a summary, not legal advice.
Review our documentation
Formal legal documents live on app.revealos.com. Reveal's security pack (technical controls, data flows and the full subprocessor register) is available on request.
REVEAL PROCESSING BOUNDARY