> What Reveal can and can't access, what your accountant sees, and how data is handled. The Reveal Trust Centre for clients, practices and IT reviewers.

Page: Trust Centre · Reveal · https://www.revealos.com/trust

Trust Centre

# What Reveal can see, and what it can't.

Reveal is the financial evidence and context layer between the systems where financial activity happens and the systems where accounting work gets done. This page is written for three readers: a client deciding whether to connect, a practice owner doing due diligence, and an IT or compliance reviewer. Each section starts in plain English. Technical detail sits underneath.

Only approved sources The client chooses what to connect, and can disconnect it any time.

Read-only email Reveal can't send, modify or delete email.

Evidence, not inboxes Your accountant sees financial documents with their source. Never a mailbox.

Credentials encrypted Tokens and logins are encrypted before storage and never shown back.

Overview PUBLISHED

## Overview

Reveal connects only to sources a client approves, retrieves financial evidence from them, and gives the practice that evidence with its context. Never the underlying mailbox, supplier account or drive.

Ask about this

For clients: what you're connecting → Why Reveal may need a supplier password → For practice owners: UK GDPR → For IT: credentials and encryption →

Connected sources PUBLISHED

## Email access — Gmail, Outlook / Microsoft 365, Yahoo Mail, AOL Mail and IMAP

Reveal connects to email to retrieve financial evidence. It can't send, modify or delete messages. Relevant evidence is surfaced into Reveal; your accountant is not given a general inbox browser.

Provider How it connects Reveal can

Gmail Google OAuth Read the mailbox, read-only

Microsoft 365 / Outlook Microsoft authentication Read mail, read-only

Yahoo Mail Yahoo-family provider authentication Read mail

AOL Mail Yahoo-family provider authentication Read mail

IMAP / compatible Mailbox or app credential, IMAP over TLS Read only; never uses SMTP

- **OAuth permission vs stored credential**: With OAuth, the provider issues Reveal a revocable token and Reveal never sees your password. With IMAP, you give Reveal a mailbox or app credential, which is encrypted before storage and never displayed back.
- **Disconnecting IMAP**: Disconnect removes Reveal's stored credential. If you created an app password for Reveal, revoke it with your provider as well.
- **Exact scopes per provider**: Gmail: gmail.readonly, userinfo.email. Microsoft 365 / Outlook: offline_access, Mail.Read, User.Read. Yahoo Mail / AOL Mail: openid, email, mail-r. No permission to send, modify or delete mailbox content is requested.

## Supplier portal access

Supplier portals don't offer read-only connections the way email providers do. To retrieve invoices, Reveal signs in to the supplier account with the client's approval. That login is protected as carefully as a mailbox permission, and the practice never gets a browser into the account.

- Credentials are never displayed through Reveal
- A rejected supplier password is deleted immediately
- The stored supplier credential is deleted on disconnect
- If the supplier asks for a one-time code, Reveal asks you for it. It's used for that sign-in only and isn't kept

1. 01 Client connects the supplier account Signs in with the supplier, with their approval CLIENT
2. 02 Sign-in encrypted Held separately from product data and never displayed ENCRYPTED
3. 03 Reveal retrieves Only supported financial documents, such as invoices and receipts REVEAL
4. 04 Financial evidence Linked to the payment, with source and time EVIDENCE
5. 05 Accounting workflow The practice sees evidence. Never the login, never the account PRACTICE

- **New portals**: Any supplier portal can be added after a one-day review.

## WhatsApp Business

Reveal connects to a WhatsApp Business account through the WhatsApp Business Platform. It never logs in to personal WhatsApp. The business connects explicitly, and receipts or invoices sent to that business number can feed Reveal as evidence.

1. 01 Connected WhatsApp Business account Connected explicitly by the business CLIENT
2. 02 Business message or document A supplier sends a receipt or invoice SENDER
3. 03 Provider event Delivered by the WhatsApp Business Platform PROVIDER
4. 04 Reveal Reads the document and its context REVEAL
5. 05 Financial evidence Joins the financial story EVIDENCE

- **Platform**: WhatsApp Business Platform (Cloud API).
- **Message content retention**: Ordinary conversation text that isn't financial evidence is not retained. Non-document messages may be processed transiently to check whether they relate to evidence, but their body text isn't stored. Where text is needed to explain an attached document, only that supporting text is kept with the evidence, on the same retention period. Reveal doesn't archive WhatsApp conversations.

## OneDrive

A Microsoft Graph connection with a read-only, least-privilege approach. Connect the locations where financial evidence lives; Reveal retrieves supported evidence from those approved locations. It doesn't need edit or delete rights.

1. 01 Connect Microsoft The client signs in with Microsoft CLIENT
2. 02 Approve the locations where evidence lives The smallest useful scope CLIENT
3. 03 Reveal reads supported files Read-only REVEAL
4. 04 Financial evidence Surfaced with its source EVIDENCE

- **Graph permissions requested**: Delegated Microsoft authentication with openid, profile, offline_access, User.Read and Files.Read: the least-privileged permission for reading the signed-in user's files. Reveal does not request Files.ReadWrite.

## SharePoint

Give Reveal access to the smallest useful area. An authorised Microsoft administrator approves a specific SharePoint site, and Reveal gets read-only access to that site, not the whole organisation.

Concept What it means

Provider permission What Microsoft authorises Reveal to access

Approved retrieval scope The specific locations the business has approved

Practice visibility The evidence and context surfaced into Reveal

- **Site selection**: Selected-site basis. During setup an authorised Microsoft administrator selects or approves the site; Reveal stores the approved site ID and, where applicable, document-library or folder IDs. The grant is read-only.
- **Exact scopes**: openid, profile, offline_access, User.Read and Sites.Selected. Reveal does not request tenant-wide Sites.ReadWrite.All.

## Uploads

Documents added directly by the client or the practice join the same financial story, carrying who uploaded them and when.

- **File types and limits**: PDF, PNG and JPG/JPEG, up to 25 MB per file. Files are checked by their actual signature, not just the extension.
- **Malware scanning**: Every upload is scanned by an antivirus engine before entering the evidence pipeline. Files that fail validation, are detected as malicious, or can't be scanned are rejected and never reach OCR, AI processing or the accounting workflow.

Access PUBLISHED

## Access & visibility

Source access is not practice visibility. Reveal may need enough technical access to a connected system to retrieve evidence. That doesn't give the accounting practice access to that system.

1. 01 Connected source Email, supplier portal, WhatsApp Business, OneDrive, SharePoint SOURCE
2. 02 Approved technical access OAuth, encrypted credential or approved location, as each source requires BOUNDARY
3. 03 Reveal processing Retrieve, read, associate, explain REVEAL
4. 04 Relevant financial evidence and context Documents, payment, timing and reasons EVIDENCE
5. 05 Accounting practice No mailbox browser, no supplier login, no drive explorer PRACTICE

## Reveal personnel access

Customer information may be accessed by authorised Reveal personnel where necessary to operate, support or secure the service. Access uses individual identities, multi-factor authentication and role-based controls, and sensitive access is recorded.

- A separate identity for every authorised staff member
- Multi-factor authentication enforced
- Role-based access controls
- Every sensitive customer-data read logged against the individual
- Detailed technical controls are in Reveal's security pack, available on request from hello@revealos.com.

Security PUBLISHED

## Credential protection

Connection credentials and access tokens are encrypted before storage, decrypted only when needed to connect to an approved source, and never displayed back through the product.

- Credentials are held separately from evidence and product data
- Stored credentials are deleted when a source is disconnected
- Detailed technical controls are in Reveal's security pack, available on request from hello@revealos.com.

- **Algorithm**: AES-256-GCM.

## Encryption

Connections between Reveal, users and connected providers use encrypted transport such as TLS. Credentials and tokens are encrypted with AES-256-GCM before storage.

- **In transit**: TLS.
- **Credentials at rest**: AES-256-GCM.
- **Evidence and application data at rest**: Encrypted at rest with AES-256, including backups.

## Authentication & privileged access

Practice users sign in with a passwordless magic link. Reveal staff and infrastructure accounts use multi-factor authentication, and production access follows least privilege.

- **Staff MFA**: Enforced.
- **Practice MFA and SSO**: Practice users sign in with a passwordless magic link, so there's no password to steal. Single sign-on and additional MFA aren't currently offered as separate options. Privileged Reveal staff access is separate and requires MFA.

## Practice isolation

Information is scoped to the practice and client workspace it belongs to: clients, connections, evidence and ledger links. Internal privileged access is controlled separately.

PRACTICE A Clients · connections · evidence · ledger links

SEPARATED FROM

PRACTICE B Clients · connections · evidence · ledger links

Data PUBLISHED

## Data lifecycle

Follow a piece of evidence from connection to deletion. Choose a stage to see what's involved.

- **Purpose**: The client chooses a source to connect
- **Information**: Which source, and the account it belongs to
- **Source permission**: None yet
- **Practice visibility**: That a source has been connected
- **Credentials**: Nothing stored yet
- **Control**: The client can stop at any point

- **Purpose**: Approve access with the provider, or enter a supplier or IMAP credential
- **Information**: An OAuth token or a credential
- **Source permission**: Read-only for email; approved locations for cloud storage; sign-in for supplier portals
- **Practice visibility**: Never sees tokens or credentials
- **Credentials**: Encrypted with AES-256-GCM before storage; never displayed
- **Control**: Revocable at the provider or in Reveal

- **Purpose**: Fetch candidate financial evidence
- **Information**: Messages, files and portal documents within the approved scope
- **Source permission**: Used only within that scope
- **Practice visibility**: Nothing yet
- **Credentials**: Decrypted only at the moment of use
- **Control**: Privacy controls skip sensitive topics and sender domains

- **Purpose**: Read, extract, associate and explain
- **Information**: Document contents, amounts, dates, references
- **Source permission**: No further access needed
- **Practice visibility**: Nothing yet
- **Credentials**: Not involved
- **Control**: AI processing disclosed under AI & model processing

- **Purpose**: Keep the financial evidence and why it belongs
- **Information**: Evidence documents, source, timestamps, match reasons
- **Source permission**: Not involved
- **Practice visibility**: Evidence with provenance
- **Credentials**: Held separately from evidence
- **Control**: Scoped to the practice and client workspace

- **Purpose**: The practice reviews and sends to the ledger
- **Information**: Evidence and ledger records
- **Source permission**: Not involved
- **Practice visibility**: Evidence, decisions and actions
- **Credentials**: Not involved
- **Control**: Every action recorded in the audit trail

- **Purpose**: End access, and manage what was retrieved
- **Information**: Stored tokens and credentials; previously retrieved evidence
- **Source permission**: Ends immediately on disconnect
- **Practice visibility**: Retrieved evidence follows the retention policy
- **Credentials**: Deleted on disconnect
- **Control**: Retention and deletion policy; IMAP app passwords revoked at the provider

## Retention & deletion

Disconnecting and deleting are different things, so here they are side by side.

- Disconnecting stops future retrieval and deletes the stored credential or token. Evidence already retrieved remains available to the accounting practice until the practice instructs Reveal to delete it or the applicable retention period expires.
- If you created an IMAP app password, revoke it with your email provider too.

Information Kept for

Connection credentials and OAuth tokens While the connection is active. Deleted on disconnect

Temporary 2FA codes Not retained

Evidence documents and extracted data Under the practice's retention instructions while it uses Reveal, including after a client disconnects; deleted within 90 days after termination unless earlier deletion is requested or retention is legally required

Unmatched retrieval working data Up to 90 days

Security and audit logs 12 months

Support information 180 days

Account and profile information The relationship plus up to 90 days

Billing and contractual records Up to six years where required by law

Backups 30 days

- **Deletion requests**: The practice, as controller, can instruct deletion through Reveal support or the privacy and compliance contact, hello@revealos.com. Reveal acknowledges within 5 business days, removes live production data within 30 days, prevents restoration into normal use, and lets backup copies expire within a further 30 days. Data that must be kept for legal, contractual, fraud-prevention or security reasons is isolated from normal product use.

[Privacy Notice ↗](https://app.revealos.com/privacy)

## Auditability

Important access and actions leave a trace.

- Source connected or disconnected
- Evidence retrieved
- Document viewed or downloaded
- Matching and association decisions
- Ledger actions
- Privileged and administrative access, attributed to the individual

- **Log retention**: Sensitive security and access logs: at least 12 months.
- **Audit export for practices**: Practice administrators can export their own Activity / Audit Log as CSV or JSON, filtered by date, with timestamp, actor, client, action, source, outcome and reference ID. A practice can't export another practice's audit information.

AI & vendors PUBLISHED

## AI & model processing

Reveal is AI-native, and we explain what AI does and where your information goes. It reads documents, extracts data, understands evidence, associates and matches it, assists supplier-portal navigation, explains its reasoning, powers Ask Reveal and keeps working in the background.

- Reveal does not train cross-customer Reveal models on client information unless separately authorised.
- External model providers' retention and training settings are disclosed separately, below.

Provider Purpose Location Training

Mistral AI OCR when Reveal's own reader can't reliably extract a document EU by default Training disabled

Anthropic (Claude API) AI reasoning, including Ask Reveal United States Not used for training

Reveal-hosted PaddleOCR Local OCR for supported documents and images Reveal infrastructure No external retention or training

## Subprocessors

The companies that process information on Reveal's behalf. Reveal assesses each provider before customer data is routed through it. The full register, with what each receives, retention and transfer safeguards, is in the Data Processing Agreement and available on request.

- International transfers are covered by Standard Contractual Clauses with the UK Addendum, or equivalent safeguards
- Not treated as subprocessors: Google, Microsoft, Yahoo/AOL and connected accounting systems, when they are the source or destination the customer chose. Stripe acts separately for Reveal billing.

Provider Purpose Location

Railway Application hosting and database EU West (Amsterdam)

Cloudflare R2 Document and backup storage EU

Resend Email delivery United States

Browserless Supplier retrieval infrastructure UK and United States

PostHog Product analytics EU (Frankfurt)

Mistral AI Document OCR EU

Anthropic AI processing United States

Slack Internal alerts United States

## Security operations

What's in place to run Reveal securely. Reveal doesn't claim certifications it hasn't confirmed. Report a security concern to the privacy and compliance contact, hello@revealos.com.

- Detailed technical controls are in Reveal's security pack, available on request from hello@revealos.com.

- **Incident handling**: Documented incident response, including notifying affected practices.
- **Backups**: Encrypted backups, kept for 30 days.
- **Vulnerability management**: Dependency and secret scanning, blocking checks before deployment, and regular patching.
- **Business continuity**: Documented continuity and recovery process; restores are tested periodically.
- **Certifications**: Reveal Technologies Ltd does not currently claim SOC 2, ISO 27001, Cyber Essentials or Cyber Essentials Plus. Some infrastructure providers hold their own certifications; those are not Reveal certifications.

Compliance PUBLISHED

## UK GDPR

The accounting practice generally acts as Controller for its client processing. Reveal acts as Processor when processing client information on the practice's instructions, and separately as Controller for its own account and billing information. This is a summary, not legal advice.

- **Processing purpose**: Retrieving, organising and explaining financial evidence for the practice's accounting work.
- **Information categories**: Financial documents and their content, source and account identifiers, payment and ledger records.
- **Security controls**: See Credential protection, Encryption and Reveal personnel access.
- **Subprocessors**: See Subprocessors.
- **Retention and deletion**: See Retention & deletion.
- **Data-subject assistance**: The practice remains the main contact for the data subject. Reveal helps locate, export, correct, restrict or delete relevant information and explain processing; it acknowledges within 5 business days and aims to complete within 30 days.
- **Breach notification**: Reveal notifies the affected practice without undue delay and no later than 48 hours after becoming aware, with the nature of the incident, likely impact, affected information where known, containment measures and a contact, followed by updates as the investigation progresses. The practice decides any notification it must make to the ICO or data subjects.

[Data Processing Agreement ↗](https://app.revealos.com/legal/dpa)

## Review our documentation

Formal legal documents live on app.revealos.com. Reveal's security pack (technical controls, data flows and the full subprocessor register) is available on request.

[Privacy Notice ↗](https://app.revealos.com/privacy) [Terms of Service ↗](https://app.revealos.com/terms) [Data Processing Agreement ↗](https://app.revealos.com/legal/dpa) [Legal & Privacy ↗](https://app.revealos.com/legal) Subprocessors → [Security pack · password on request →](https://www.revealos.com/security-pack) [Contact · hello@revealos.com →](mailto:hello@revealos.com)
