Skip to content

Security and governance

Agents you can let
near the business.

RevTech runs the agents, which means RevTech carries the operational burden of running them safely — the permissions, the approval gates, the audit record, and the evaluation that proves they are working. Your CRM stays the system of record throughout.

Controls

Seven things an enterprise needs from agentic work.

Each of these is a property of the managed service, not a feature your team configures and maintains.

Observability

Every agentic action is visible. Admins and leaders can see what agents did across the GTM organization, on what basis, and at what cost.

  • Which agents ran, when, for whom, and why
  • Which objects, fields, documents, and records were used
  • Which model was used, with consumption, latency, and error rate
  • Which APIs, connectors, and workflows were called

Managed infrastructure

RevTech operates the runtime, orchestration, scaling, and upgrades. There is no agent infrastructure for your team to deploy, patch, or keep available.

  • Agent runtime and orchestration operated by RevTech
  • Model routing maintained as the provider landscape changes
  • Upgrades and improvements land without a project on your side
  • No customer-side platform team required

Auditable agentic actions

Every action carries its actor, timestamp, evidence, and prior state. That record is what makes agent work reviewable after the fact and reversible when it is wrong.

  • Complete action history per agent and per record
  • Approvals, edits, and rejections captured with their approver
  • Evidence retained alongside the action it justified
  • History available to you, not held as internal telemetry

Resource allocation

Agent work consumes credits, and consumption is bounded. Limits on volume and rate keep both cost and blast radius predictable.

  • Consumption visible per agent and per motion
  • Volume and rate limits on what an agent may change in a period
  • Spend predictable rather than discovered at invoice
  • Scope changes are a deliberate act, not a drift

Data controls

Your CRM stays the system of record. RevTech assembles the context agents need to work, under controls on what is used, where it travels, and how long it is retained.

  • Your systems remain the source of truth
  • Context assembly scoped to what an agent is permitted to see
  • Defined retention for operating data and audit records
  • Customer data is not used to train third-party foundation models

Permissioning

Agents connect with scoped, least-privilege access that honors your existing roles and sharing rules. Permissions are set per agent, so widening one does not widen the rest.

  • Least-privilege access honoring your profiles and sharing rules
  • Per-agent scopes rather than one platform-wide grant
  • Write access granted separately from read access
  • Approver rights follow your existing permission model

Evaluation and quality control

Agent output is evaluated continuously, with human edit and rejection rates as the strongest signal. Quality regressions surface as data before they surface as complaints.

  • Human edit and rejection rates tracked per agent and action type
  • Output checked against expected structure and evidence
  • Anomalies in volume or behavior flagged against normal patterns
  • Escalation when an agent cannot source what it needs to act

Compliance

Where we are, stated plainly.

We publish status rather than badges. Request current documentation and we will share it, under NDA where required.

GDPR

Data processing terms available on request.

Sub-processors

Current list available on request.

Penetration testing

Summary available under NDA.

Security questions we get asked

No. Your CRM remains the system of record. RevTech reads and writes through the systems you already own and adds an auditable record of what agents did on top of them.
Customer data is not used to train third-party foundation models. RevTech routes work to models to perform tasks, and evaluates output quality internally to improve the service.
Scoped, least-privilege access that honors your existing roles and sharing rules. Permissions are granted per agent, and write access is granted separately from read access.
Yes. Approval thresholds are configured per agent and per action type. The default posture is that consequential actions wait for a person, and you widen that as the recorded history justifies it.
Contact us and we will share current attestation status, the sub-processor list, data processing terms, and penetration test summaries under NDA where required.
Data is stored in the region agreed in your contract and processed by the sub-processors on the list we publish on request. Changes to that list are notified in advance, so a new sub-processor is never introduced silently.
Your CRM is the system of record throughout, so the operational data never left your systems in the first place. What RevTech holds is the audit record of agent activity and the context assembled to produce it, and that is exported to you on request and deleted on the schedule set in your agreement.
No. Every action an agent performs is recorded with what it did, which records it touched, the context it drew on, and who approved it where approval was required. That record exists whether or not anyone goes looking for it, which is what makes it evidence rather than a log.
Three things, in order. Scope limits what a given agent may touch at all. Approval gates hold consequential and customer-facing work for a person regardless of volume. Resource limits cap how much any agent can execute in a period, so a misconfiguration is bounded rather than unbounded while it is being caught.
Continuous evaluation against held-out cases, plus the rejection signal from real reviewers. An agent whose output starts being rejected more often is surfaced before the pattern reaches a customer, and that evaluation is part of the managed service rather than something your team runs.
Access is least-privilege and role-based internally as well as externally. Support and delivery staff access customer environments only where a request or an incident requires it, and that access is logged the same way agent activity is.
Demo

Try the demo.

See agents carry the repeatable work of GTM across sales, marketing, customer success, and RevOps. Every action prepared, reviewed, and recorded. Fictional data, real product.

Explore the demo