Security

How Revela looks after your data

An honest summary of how Revela is built to protect what you store and share. The code is public: anyone can check it.

Connections and sessions

All connections are encrypted (HTTPS). Your session lives in a secure cookie that pages cannot read, and the server only stores a fingerprint of each session. In My account you can see your open sessions and sign them out.

The server decides

The app only asks: the plan, the credits and each person’s permission on each presentation (present, view, comment or edit) are checked on the server in every operation.

Sealed links

A presentation shared by sealed link is encrypted in your browser (256-bit AES-GCM) before it leaves. The key travels in the link itself or is derived from a password, so the server stores something it cannot read.

Who gets in

Teams can sign in with their identity provider (SSO with OpenID Connect: Microsoft Entra ID, Okta, Google Workspace, Keycloak), with their domains verified in DNS. Links support a password, an expiry date, a specific domain and present-only with no copying.

Where the data is

Revela is hosted on Cloudflare. Some providers are in the United States; those transfers are covered by the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses. Details in the privacy policy and the data processing agreement.

Outside content, cleaned

The files you open, what you paste and the changes from people editing with you are cleaned before they’re used: no scripts or frames, only safe links and fonts.

Found a security flaw?

Tell us privately, not in public: on GitHub, in the Security ▸ Report a vulnerability tab of fmesasc/revela, or through the contact form, choosing “Privacy” and saying it’s a security report.

Say which part is affected, how to reproduce it and what an attacker could do. Don’t access other people’s data or run tests that degrade the service. We’ll reply within a few working days and, if you like, credit you once it’s fixed.