Security & Trust
Security and Trust at Revox AI
Built for the sensitive work insurance agencies perform every day
Revox AI helps insurance agencies answer calls, collect applicant and policyholder information, communicate by voice and text, organize service requests, connect with agency systems, and—where enabled—complete authorized workflows in third-party insurance portals.
That work can involve confidential business information and personal information about applicants, policyholders, household members, drivers, employees, claimants, and other individuals. We therefore design Revox around a simple principle: information should be used only for the authorized workflow, made available only to the people and systems that need it, and protected throughout its lifecycle.
Revox uses a multi-provider cloud architecture. There is not one physical “Revox server” or one data center through which every feature operates. Different components provide application hosting, telecommunications, voice generation, language-model processing, knowledge retrieval, payments, and integrations. This page explains that architecture, the kinds of information each component may process, how information moves through the service, and the responsibilities shared by Revox, our infrastructure providers, and our customers.
Security at a glance
- Cloud-based architecture. Revox uses established cloud, communications, AI, database, and payment providers instead of operating physical servers in an office.
- Primarily U.S.-based core hosting. Revox’s primary application and data infrastructure is designed around U.S.-based hosting. Certain specialized providers may process data through distributed or international infrastructure depending on the feature, account configuration, routing, support requirements, and the provider’s own subprocessors.
- Encryption in transit. Revox uses HTTPS/TLS-protected connections for supported web and API communications. Our infrastructure providers also supply encryption controls for their respective services.
- Encryption at rest. Customer information stored in supported platform databases and storage services is protected using the at-rest encryption provided by the applicable hosting or database platform.
- Account and tenant controls. Revox uses authenticated accounts, application privacy rules, and account-level data restrictions to limit access to the appropriate customer environment.
- Limited administrative access. Revox personnel access customer information only when reasonably necessary to provide, support, secure, investigate, or maintain the service, and subject to role, confidentiality, and operational requirements.
- Controlled integrations. Revox transmits information to an agency management system, carrier, rater, communications service, or other destination only when the customer has connected or selected that destination or the transfer is otherwise necessary to deliver the configured service.
- Customer-controlled workflows. Customers determine which agents, integrations, destinations, knowledge sources, scripts, phone numbers, and workflows are enabled for their account.
- Data minimization. Revox is designed to process the information needed to perform the configured task. Customers should not submit information that is unnecessary for the applicable insurance or service workflow.
- Human review where it matters. AI and automation can make mistakes. Revox is not a substitute for licensed insurance judgment, required applicant certifications, or customer review of applications, quotes, coverages, policy changes, and binding decisions.
Where Revox data is hosted and processed
The short answer
Revox does not operate from a single server location. Our primary application environment and core data services are designed to use U.S.-based cloud infrastructure. However, Revox also relies on specialized providers for telephony, AI, voice, messaging, vector search, payments, and connected systems. Depending on the feature and configuration, those providers or their subprocessors may process information in additional locations.
For that reason, Revox does not represent that every byte of customer information remains in one state, one data center, or exclusively within the United States unless that commitment is expressly stated in a customer-specific written agreement and supported by the applicable technical configuration.
| Component | Primary purpose in Revox | Location approach |
|---|---|---|
| Revox application platform | Customer portal, configuration, records, workflows, support functions, and application data | Hosted through Bubble’s AWS-based infrastructure. The precise location depends on the applicable Bubble deployment and account configuration. |
| Revox backend services | API orchestration, integration logic, workflow processing, and supporting services | Hosted through Render in the region selected for the relevant service. Render offers U.S. and non-U.S. regions; Revox’s actual production selection must govern any customer-specific statement. |
| Cloud storage and security services | Storage, encryption capabilities, infrastructure, and supporting cloud functions where used | Hosted through AWS in the region selected for the applicable Revox or provider component. AWS is not the exclusive host for every Revox feature. |
| Voice-agent platform | Voice synthesis, speech processing, conversational-agent execution, conversation data, and related analytics | Provided by ElevenLabs. Standard ElevenLabs customer data storage is U.S.-based according to its published documentation, while processing or support may occur elsewhere. Enterprise isolated-region options require separate configuration. |
| Language-model processing | Understanding requests, generating responses, classification, extraction, summaries, and workflow reasoning | Provided through the OpenAI API. Storage and processing location depend on the Revox project configuration, endpoint, model, feature, and any residency controls enabled for that project. |
| Telecommunications | Phone numbers, voice routing, call signaling, call media, recordings where enabled, and SMS delivery | Provided through Twilio. Location and data handling depend on the Twilio product, region, routing, and account configuration used for the communication. |
| Knowledge retrieval | Embeddings, semantic search, knowledge-base retrieval, metadata, and related vector records | Provided through Pinecone. The cloud and region selected when the relevant index is created determine the deployment location for that index. |
| Payments | Subscription checkout, payment processing, billing identifiers, and payment status | Provided through Stripe. Payment data is processed within Stripe’s infrastructure; Revox generally receives the billing and transaction information needed to administer the subscription rather than full payment-card details. |
| Source code and deployment operations | Version control, code collaboration, deployment workflows, and software-change history | Provided through GitHub. GitHub is used for software development and is not intended to serve as Revox’s primary customer-record database. |
| Customer-connected systems | Agency management systems, CRMs, email and calendar tools, carrier portals, comparative raters, and other customer-authorized destinations | Information is processed under the configuration of the connection and the independent system’s own hosting, security, retention, and privacy practices. |
Customers with a contractual data-location requirement should contact Revox before enabling the affected feature. A customer-specific answer requires reviewing every component used by that customer—not only the location of the main web application.
How information moves through Revox
The exact path depends on the feature. A typical voice and insurance-intake workflow may operate as follows:
- 1A caller contacts a telephone number connected to Revox, or an authorized user starts a web or messaging interaction.
- 2The telecommunications provider routes the call or message to the configured Revox voice-agent service.
- 3The voice and language-processing services convert speech into usable conversational context, determine the appropriate response, and generate synthetic speech or text.
- 4Revox collects the fields required by the customer’s configured workflow, such as contact, driver, vehicle, property, policy, coverage, incident, appointment, or service-request information.
- 5The application stores or updates the authorized record and may generate a transcript, summary, structured intake record, notification, document, or task.
- 6If the customer has enabled an integration, Revox sends the authorized information to the selected agency system, CRM, email recipient, calendar, webhook, carrier, rater, or other configured destination.
- 7Revox records sufficient operational information to display results, support the workflow, diagnose errors, protect the service, and meet applicable legal or contractual obligations.
- 8Information does not necessarily pass through every Revox provider. For example, a billing transaction does not need to pass through the voice platform, and source code stored in GitHub is separate from application records stored in the Revox platform. Data flow is determined by the feature used and the customer’s configuration.
Information Revox may protect and process
Depending on the services enabled, Revox may process:
- Customer account, organization, user, billing-contact, and support information.
- Call audio, recordings where enabled, transcripts, summaries, telephone numbers, routing records, timestamps, and call outcomes.
- SMS messages, delivery records, consent or opt-out information, and appointment links.
- Email content, attachments, calendar information, and service requests where an applicable connection is enabled.
- Applicant, policyholder, claimant, household-member, driver, employee, beneficiary, or business information supplied for an authorized insurance workflow.
- Driver, vehicle, property, business, coverage, policy, loss, accident, claim, payroll, employment, and underwriting information.
- Files such as declaration pages, applications, loss runs, ACORD forms, schedules, supporting documents, and carrier correspondence.
- Customer scripts, prompts, agent settings, workflow definitions, custom fields, routing instructions, knowledge-base documents, and integration settings.
- Structured outputs and derived information, including extracted fields, summaries, classifications, matching results, task outcomes, and vector embeddings.
- Integration authentication material, which may include access tokens, refresh tokens, API keys, session identifiers, usernames, or passwords depending on the connection method.
- Technical and security records such as IP address, device and browser information, login events, API events, diagnostic logs, integration errors, and task history.
Not every category is collected for every customer or interaction. The availability of a feature does not mean that every kind of sensitive information is appropriate for that feature. Customers should configure workflows to collect only the information needed for their authorized business purpose.
Encryption and secure transmission
Data in transit
Supported Revox web and API communications use HTTPS/TLS to protect information while it travels between the user, Revox, and participating providers. Third-party portals and customer-connected systems control the security of their own endpoints. Revox cannot guarantee the security of a destination that a customer selects or controls.
Telephone calls and SMS messages also depend on public and carrier telecommunications networks. Revox uses established communications providers, but ordinary telephony and messaging should not be treated as equivalent to a private end-to-end encrypted messaging channel.
Data at rest
Revox relies on the storage encryption supplied by the applicable platform or database provider for supported stored data. For example, Bubble publishes that data in its AWS-hosted environment is encrypted at rest through its database infrastructure, and Pinecone publishes that its vector data is encrypted at rest. AWS encryption capabilities may protect applicable Revox-controlled components, but not every Revox provider or third-party portal runs inside Revox’s AWS environment.
Revox does not claim that all data is protected by one encryption product, one key-management system, or customer-managed keys. Encryption implementation depends on the system in which the information is stored.
Identity, authentication, and access
Customer access
Users access Revox through authenticated accounts and the permissions available for their organization. Customers are responsible for:
- Providing accounts only to authorized personnel.
- Using unique credentials and strong passwords.
- Enabling multi-factor authentication where the applicable platform or connected system supports it.
- Removing access promptly when a user changes roles or leaves the organization.
- Protecting email accounts and devices that can receive password resets, magic links, one-time codes, or administrative notifications.
- Reviewing which integrations, phone numbers, agents, workflows, and recipients are connected to their account.
- Promptly notifying Revox of suspected unauthorized access.
Revox administrative access
Authorized Revox personnel may access customer information when reasonably necessary to configure an account, provide support, investigate a reported issue, monitor service operation, address abuse or security risks, restore functionality, or comply with law. Access is intended to be limited to personnel with a legitimate operational need and subject to confidentiality obligations.
Support access may expose information contained in a transcript, task log, integration response, or screenshot. Revox personnel are expected to use that access only for the applicable support, operational, security, or legal purpose.
Service-to-service access
Revox components communicate with providers and connected systems through supported APIs, webhooks, tokens, service credentials, and authenticated sessions. Credentials and tokens are treated as sensitive operational information. Access should be scoped to the permissions required by the integration where the third-party system supports that level of control.
Customer separation and application privacy
Revox is a multi-customer service. Application privacy rules and account-level identifiers are used to restrict records to the appropriate customer environment. Workflows, integrations, recipients, and agent configurations are associated with the relevant customer account so that one customer’s configuration is not intentionally used to perform work for another customer.
No application architecture eliminates all risk. Revox reviews and maintains its access logic as the product evolves, and customers should report any unexpected visibility or access behavior immediately.
Voice, call recording, transcription, and messaging security
Revox voice agents may receive or place calls, generate synthetic speech, transcribe conversations, create summaries, collect structured data, route calls, transfer calls, schedule appointments, and send follow-up messages. Depending on configuration, audio and conversation history may be retained by Revox or its voice and communications providers.
Customers control their business purpose, scripts, workflows, recipients, and use of recording. Customers are responsible for providing any notices and obtaining any permissions required for:
- AI-generated or synthetic voice interactions.
- Call recording and transcription.
- Automated, artificial, or prerecorded voice calls.
- Marketing or informational calls and messages.
- SMS enrollment, opt-out handling, and message content.
- Use of applicant and policyholder information.
Revox supports privacy-conscious configuration. ElevenLabs provides settings for conversation retention, audio saving, redaction, and—on qualifying enterprise arrangements—zero-retention modes. A provider capability applies to Revox only when Revox has actually enabled and configured it for the relevant workspace or customer use case.
AI processing and model training
Revox uses AI to understand requests, carry on conversations, extract information, classify intent, generate responses and summaries, retrieve relevant knowledge, and assist with configured workflows.
Revox does not sell Customer Data. Revox does not use Customer Data to train a broadly available generalized Revox model unless the customer expressly agrees in writing to that use. Revox may use operational information to provide, secure, support, and improve the service in accordance with its agreements and Privacy Policy, including testing and evaluating product performance with appropriate safeguards.
OpenAI states that information submitted through its API is not used to train or improve OpenAI models unless the API customer affirmatively opts in. OpenAI’s default abuse-monitoring and application-state retention can vary by endpoint and configuration. Zero Data Retention and regional controls are separate, eligibility-based settings and should not be assumed to apply unless confirmed for the Revox project in use.
Other AI and voice providers operate under their own enterprise or API terms, account settings, and retention options. Revox evaluates those terms and configurations for the applicable use, but does not represent that every provider offers identical training, retention, or geographic controls.
AI-generated and extracted information may be incorrect, incomplete, or outdated. Revox customers must review material insurance information and decisions rather than treating an AI response or automation status as an independent guarantee.
Knowledge bases, embeddings, and retrieval
Customers may provide files, URLs, text, instructions, scripts, and other sources to help an agent answer questions or complete a workflow. Revox may divide those sources into smaller sections, create mathematical representations known as embeddings, attach metadata, and store them in a vector database so relevant information can be retrieved during an interaction.
An embedding is not automatically anonymous. It may still be connected to customer content, metadata, or an identifiable person. Revox therefore treats embeddings and related metadata as Customer Data where they can be linked to the customer or an individual.
Customers should not place secrets, portal passwords, payment-card data, or unnecessary sensitive personal information in an agent knowledge base. Knowledge sources should be reviewed for accuracy, authorization, and appropriate audience before they are activated.
Integrations and third-party destinations
Revox can exchange information with customer-selected systems through APIs, webhooks, email, SMS, file transfer, or other supported methods. Connected systems may include agency management systems, CRMs, communications services, calendars, carriers, raters, and other insurance technology platforms.
Before information is sent, customers should verify the destination, recipient, integration account, and enabled workflow. Once information reaches a carrier or another independent recipient for its own business purpose, that recipient controls its own copy under its agreements, privacy notice, retention rules, and legal obligations. Disconnecting Revox does not recall information already transmitted or delete records independently retained by the receiving system.
Logging, monitoring, and audit information
Revox and its providers maintain operational records needed to run and protect the service. Depending on the feature, those records may include login events, call and message status, workflow state, integration requests, delivery status, API responses, portal errors, task actions, timestamps, diagnostic information, and security-relevant events.
These records help Revox:
- Confirm whether a task or message was attempted or completed.
- Diagnose service and integration failures.
- Investigate suspected unauthorized activity or abuse.
- Support customers and reproduce reported issues.
- Maintain availability, performance, and security.
- Satisfy contractual, legal, accounting, or dispute-resolution needs.
Logs can contain Customer Data. Access and retention therefore depend on the purpose of the record, the service configuration, the provider involved, and applicable contractual or legal requirements.
Secure development and change management
Revox uses version-controlled development and deployment processes for its custom services. GitHub supports source-code management, collaboration, review history, and deployment workflows. Production hosting is separated from the source-code repository, and GitHub is not intended to be used as the primary storage location for call transcripts, applicant records, policy information, or portal credentials.
Revox tests changes before production use based on the scope and risk of the change. Updates may include new functionality, integrations, security improvements, dependency updates, bug fixes, workflow revisions, and provider-required changes. Urgent fixes may use an accelerated process when needed to reduce active risk or restore service.
Because Revox also relies on third-party platforms and portals, some changes originate outside Revox’s control. Revox monitors and responds to material provider changes that affect supported workflows, but cannot guarantee that a third-party API, website, carrier portal, telecommunications network, or AI model will remain unchanged or continuously available.
Vulnerability management
Revox evaluates reported security concerns based on their potential effect on confidentiality, integrity, availability, customers, and individuals. Remediation priority may consider exploitability, affected data, affected customers, availability of compensating controls, and dependencies on third-party providers.
Security researchers and customers can report a suspected vulnerability to security@revoxai.io. Reports should include the affected page or service, a description of the issue, reproducible steps, and any relevant evidence. Do not access, download, alter, or disclose another person’s information while testing, and do not disrupt the service.
Revox does not authorize destructive testing, denial-of-service activity, social engineering, credential attacks, physical attacks, spam, or testing of third-party services that Revox does not control.
Incident response
Revox maintains an operational process for evaluating suspected security incidents. Depending on the circumstances, response activities may include:
- Receiving and documenting the report or alert.
- Assessing whether customer information or service availability may be affected.
- Containing active risk, which may include disabling a credential, session, integration, workflow, or affected service.
- Investigating relevant logs, systems, providers, and customer reports.
- Correcting or mitigating the identified issue.
- Restoring service safely and monitoring for recurrence.
- Notifying affected customers or individuals when required by applicable law or contract.
- Reviewing the event and implementing reasonable follow-up improvements.
No internet-connected system can be guaranteed completely secure. Revox’s commitments are to maintain reasonable administrative, technical, and organizational safeguards appropriate to the service, respond to credible concerns, and meet applicable notification obligations—not to promise that unauthorized access can never occur.
Availability, resilience, and recovery
Revox is built on cloud providers that supply redundant and scalable infrastructure for their respective services. Revox uses provider capabilities, operational monitoring, deployment controls, and recoverability features appropriate to the relevant component.
Availability can still be affected by telecommunications carriers, internet routing, cloud incidents, AI-provider incidents, connected-system outages, expiring portal sessions, changed third-party websites, rate limits, customer configuration, maintenance, and events outside Revox’s reasonable control. Unless a separate service-level agreement says otherwise, Revox does not promise uninterrupted or error-free operation or a specific recovery time.
Data retention and deletion
Revox retains information according to the type of record, the enabled feature, customer configuration, operational need, contractual obligations, legal requirements, dispute or security needs, and the retention behavior of the provider involved.
Examples include:
- Account and billing records may be retained while the account is active and as needed for accounting, tax, fraud-prevention, dispute, and legal purposes.
- Call audio, transcripts, and conversation records may follow the retention settings configured in the voice-agent platform and Revox application.
- Customer files, knowledge sources, intake records, summaries, and service requests may remain until deleted under the applicable customer or Revox process.
- Security and diagnostic logs may be kept for an operationally appropriate period.
- Integration credentials and tokens may remain until they expire, are revoked, are disconnected, or are removed under the applicable process.
- Backups and provider-maintained copies may persist for a limited period after deletion before aging out under the relevant backup lifecycle.
- Information may be retained longer where required by law, necessary to protect the service or others, needed to resolve a dispute, or subject to a valid preservation obligation.
When a customer requests deletion or closes an account, Revox evaluates and removes information from the systems it controls in accordance with the applicable agreement, product capabilities, and legal obligations. Deletion from an active system may not immediately remove the same information from encrypted backups, security records, or a provider’s legally required records.
Deletion by Revox also cannot erase information already delivered to an agency, carrier, rater, CRM, email recipient, telecommunications provider, payment processor, or other independent recipient. Customers may need to submit a separate request to those parties.
Customers with a required retention schedule should arrange it with Revox in writing so the applicable product settings, provider capabilities, and legal requirements can be reviewed before use.
Payment security
Revox uses Stripe to process subscription payments. Payment-card information entered into Stripe-hosted or Stripe-supported payment fields is handled by Stripe under its payment-security program. Revox generally receives limited billing information, transaction identifiers, payment status, card brand, and limited card details needed to administer the subscription rather than the complete card number or security code.
Customers should never place payment-card numbers or card security codes in Revox agent prompts, knowledge bases, ordinary support messages, or intake fields unless Revox has expressly approved a dedicated workflow designed for that information.
Privacy, legal, and insurance-industry responsibilities
Security and privacy are related but distinct. Revox may act as a processor or service provider for information handled on behalf of a customer and as a controller or business for its own account, billing, website, support, and security information. The applicable role depends on the activity and law.
Insurance agencies remain responsible for their own legal basis, notices, authorizations, data accuracy, licensing obligations, carrier permissions, communications consent, recordkeeping, and employee access. Revox remains responsible for the obligations that apply to Revox and for following applicable documented customer instructions.
Revox should not be used to process protected health information or another specially regulated data category that requires a specific written agreement or certified environment unless Revox has expressly approved that use in writing and all required agreements and configurations are in place.
Our infrastructure and service providers
Revox uses providers for specific operational purposes. The provider used can change as the platform evolves, and a provider may use its own subprocessors.
| Provider | Revox use | Information that may be involved |
|---|---|---|
| Bubble | Application interface, customer accounts, database, workflows, and application operations | Account data, customer configuration, intake records, transcripts, summaries, support data, and other application records |
| Render | Hosting for custom backend and integration services | API requests, workflow payloads, identifiers, logs, integration data, and task results handled by the hosted service |
| Amazon Web Services | Cloud infrastructure, storage, and encryption capabilities for applicable components | Data stored or processed by the specific AWS-backed component |
| ElevenLabs | Conversational voice agents, speech and voice processing, call data, transcripts, and agent analytics | Audio, conversation content, transcripts, prompts, agent configuration, collected fields, and related metadata |
| OpenAI | Language-model reasoning, text generation, classification, extraction, summarization, and related AI functions | Prompts, relevant conversation or document content, structured fields, requested outputs, and technical metadata |
| Pinecone | Vector database and knowledge retrieval | Embeddings, knowledge-base content or fragments where applicable, metadata, identifiers, and retrieval queries |
| Twilio | Telephone numbers, voice routing, call connectivity, SMS, and communications records | Telephone numbers, call or message content as applicable, routing data, recordings where enabled, delivery data, and communications metadata |
| Stripe | Subscription payments and billing | Customer and billing details, payment method information, transaction identifiers, invoices, and payment status |
| GitHub | Source-code management and deployment operations | Source code, technical configuration, issue and deployment information; not intended as the primary customer-data store |
| Customer-selected systems | Agency systems, CRMs, email, calendars, carrier portals, raters, and other connected tools | The information the customer authorizes Revox to send to or retrieve from that system |
Use of a provider does not mean every Revox customer uses every provider. It also does not mean that all information described above is sent in every request.
Compliance and independent assurance
Several Revox infrastructure providers publish independent security and compliance programs, which may include SOC 2, ISO 27001, PCI DSS, GDPR-oriented contractual measures, or other frameworks applicable to their own services.
Those reports and certifications apply to the provider and the scope described in the provider’s documentation. They do not automatically certify Revox AI LLC, the Revox application, a customer’s implementation, or every end-to-end workflow.
Unless Revox expressly states otherwise in a current written document, Revox does not claim that it is independently certified under SOC 2 or ISO 27001, that every service is HIPAA compliant, that every workflow is PCI compliant, or that use of Revox by itself makes a customer compliant with any law or framework.
Revox can respond to reasonable customer security questions and discuss contractual or technical requirements appropriate to the proposed use case.
Frequently asked questions
Where exactly are Revox’s servers?
Revox uses a multi-provider cloud architecture rather than a single physical server. The primary application and core data services are designed around U.S.-based cloud hosting. Some specialized communications, AI, support, or integration providers may process information in other locations depending on the product, routing, account setting, and customer configuration. Revox will not promise a specific state, data center, or exclusive country of processing unless that commitment is confirmed for every relevant component and documented in writing.
Is customer data encrypted?
Supported web and API traffic uses HTTPS/TLS. Stored information is protected using the at-rest encryption capabilities of the applicable platform or database provider. Because Revox uses multiple providers, the exact encryption implementation is not identical across every component.
Does Revox sell customer data?
No. Revox does not sell Customer Data.
Is customer data used to train AI models?
Revox does not use Customer Data to train a broadly available generalized Revox model unless the customer expressly agrees in writing. OpenAI states that API data is not used to train its models unless the API customer opts in. Other providers are governed by their applicable business terms, API terms, and account settings.
Does Revox store call recordings?
It depends on the customer’s configuration. Audio saving and retention can vary by agent and provider setting. Transcripts, summaries, and operational call records may be retained even when audio saving is disabled if required for the configured service.
Does Revox store carrier or rater credentials?
Some connection methods require Revox to process credentials, API keys, or tokens for the connected system. Other methods allow the customer to authenticate directly with the third party. The exact method depends on the integration. Customers should use dedicated, least-privilege integration users where possible.
Is Revox SOC 2 certified?
Revox relies on providers that maintain their own security and compliance programs, and some of those providers publish SOC 2 reports. A provider’s certification does not automatically certify Revox. Revox does not claim independent SOC 2 certification unless and until Revox has completed that process and publishes the applicable scope.
Is Revox HIPAA compliant?
Revox should not be used for protected health information that requires a Business Associate Agreement unless Revox has expressly approved the use case in writing, the required agreements have been executed, and all relevant services are configured appropriately. A provider’s ability to offer a BAA does not automatically make the complete Revox workflow HIPAA compliant.
Is Revox PCI compliant?
Stripe processes Revox subscription payments under Stripe’s payment-security program. That does not make every Revox feature appropriate for payment-card data. Customers should not submit full card numbers or security codes through ordinary Revox calls, prompts, knowledge bases, support messages, or automation workflows unless Revox has approved a dedicated compliant process.
Can Revox delete information from a carrier after it is submitted?
Not necessarily. Revox can address information in systems Revox controls, subject to legal and technical limitations. A carrier, rater, agency system, email recipient, or other independent destination controls its own copy. The customer may need to contact that recipient directly.
Can Revox guarantee that automation will never make an error?
No. AI, extraction, and integrations can fail or produce incorrect results. Customers must review material insurance data, submissions, coverages, quotes, policy changes, and binding decisions.
How do I report a security concern?
Email security@revoxai.io with a clear description, the affected service or URL, steps to reproduce, and relevant evidence. For privacy requests, contact privacy@revoxai.io. For ordinary product support, contact admin@revoxai.io.
Contact Revox
Security reports
security@revoxai.ioPrivacy questions and requests
privacy@revoxai.ioCustomer support
admin@revoxai.ioRevox AI LLC
Delaware, United States
Last updated: September 11, 2026
