Bundle10KB
Queries0
Backend0
Cache Hit0%
Snapshot—
Rebel7 Procurement Center · Enterprise Documentation

Enterprise procurement documentation.

All documents required for enterprise vendor assessment. Public documents are directly accessible. Draft and contract-specific documents are available on request through your sales contact.

Document Inventory

Privacy Policy

READY

Describes data collection, usage, storage, retention, and user rights.

PUBLICView →

Exists in Legal.jsx. Updated to correct SOC 2 and penetration testing claims.

Terms of Service

READY

Governs access to and use of the Rebel7 AI Governance Engine.

PUBLICView →

Exists in Legal.jsx.

Security Overview

READY

Architecture, access control, encryption, evidence integrity, and compliance alignment.

PUBLICView →

Exists as Security.jsx. Claims verified against implementation.

Trust Center

READY

Public attestation repository with evidence integrity gate.

PUBLICView →

Exists as Rebel7TrustCenter.jsx. Procurement Center links from here.

Technology Proof

READY

Live cryptographic evidence chain demonstration with tamper detection.

PUBLICView →

Exists as TechnologyProof.jsx. Demo data clearly marked.

Subprocessor List

PARTIAL

List of third-party providers that process customer data.

PUBLICView →

Built from verified infrastructure. Some regions/transfer mechanisms require verification.

Data Processing Addendum (DPA)

REQUIRES LEGAL INPUT

Data processing agreement template for enterprise customers.

DRAFT — NOT FOR EXECUTIONView →

DRAFT — NOT FOR EXECUTION. Future S.r.l. not yet incorporated. Founder currently operates through individual Italian VAT position. Legal entity placeholder [REBEL7 LEGAL ENTITY — REQUIRED BEFORE EXECUTION] must be resolved before signing.

Service Level Agreement (SLA)

REQUIRES OPERATIONAL INPUT

Enterprise SLA draft with target service levels. Contract-specific.

AVAILABLE ON REQUESTView →

No historical uptime claimed. SLA targets marked as COMMERCIAL DECISION REQUIRED. Service credits require commercial approval.

Support Policy

REQUIRES OPERATIONAL INPUT

Support channels, severity classification, and escalation process.

AVAILABLE ON REQUESTView →

Support hours: Monday–Friday during Italian business hours. No 24/7 or weekend support. Response targets require operational decision.

Incident Response Overview

PARTIAL

Enterprise-facing incident response process overview.

PUBLICView →

Based on existing Security.jsx architecture. No 24/7 SOC or certified SOC claim. Specific response times not committed.

Data Retention & Deletion Policy

PARTIAL

Documented retention and deletion behavior.

PUBLICView →

Policy exists in Legal.jsx. Automated enforcement not implemented — deletion is manual/process-based.

Business Continuity & Disaster Recovery

REQUIRES OPERATIONAL INPUT

BCP/DR draft based on verified infrastructure capabilities.

AVAILABLE ON REQUESTView →

RTO/RPO under definition — OPERATIONAL TARGET UNDER DEFINITION. No multi-region failover, hot standby, or guaranteed restore times claimed.

Security Questionnaire Foundation

PARTIAL

Internal reusable enterprise security questionnaire knowledge base.

INTERNAL

Internal sales enablement document. Not shared externally. Some items require verification.

Subprocessor List

The following third-party providers process customer data as part of operating the Rebel7 platform. Entries marked "TO VERIFY" require confirmation of processing region or transfer mechanism.

ProviderClassificationPurposeData CategoryRegionPrivacy/DPA
Base44CONFIRMED CUSTOMER-DATA SUBPROCESSORApplication hosting platform, backend-as-a-service, build and deployment infrastructureApplication source code, environment variables, deployment metadata. Does not directly process end-user personal data.TO VERIFYLink ↗
SupabaseCONFIRMED CUSTOMER-DATA SUBPROCESSORPostgreSQL database, authentication, file storage, edge functionsUser authentication data, organization records, application data, file uploadsEU (configured)Link ↗
StripeCONFIRMED CUSTOMER-DATA SUBPROCESSORPayment processing, subscription billing, invoicingPayment method tokens, billing address, transaction records. Rebel7 does not store raw card data.TO VERIFYLink ↗
ResendCONFIRMED CUSTOMER-DATA SUBPROCESSORTransactional email delivery (trial notifications, sales sequences, whitepaper delivery)Email addresses, email content, delivery metadataTO VERIFYLink ↗
OpenAICONDITIONAL / DEPENDS ON FEATUREAI model inference for InvokeLLM integration (optional model selection)Text prompts and generated responses passed through the AI Gateway. No training on customer data.TO VERIFYLink ↗
AnthropicCONDITIONAL / DEPENDS ON FEATUREAI model inference for InvokeLLM integration (optional model selection)Text prompts and generated responses passed through the AI Gateway. No training on customer data.TO VERIFYLink ↗
GoogleCONDITIONAL / DEPENDS ON FEATUREOAuth authentication provider (Google Sign-In)Email address, name, profile picture for users who choose Google authenticationTO VERIFYLink ↗
GitHubDEVELOPMENT TOOL ONLYSource code hosting, version control, CI/CD (development tooling)Source code, commit metadata. Does not process end-user personal data.TO VERIFYLink ↗
DocuSignCONDITIONAL / DEPENDS ON FEATUREElectronic signature for compliance documents (optional Comply module)Signer name, email, signature records for documents sent through Comply moduleTO VERIFYLink ↗

Data Processing Addendum (DPA)

DRAFT — NOT FOR EXECUTION

This DPA template is provided for review purposes only. The future S.r.l. has not yet been incorporated; the founder currently operates through an individual Italian VAT position. The legal entity placeholder [REBEL7 LEGAL ENTITY — REQUIRED BEFORE EXECUTION] must be resolved before signing. Contactenterprise@rebel7.ai to request the executable version.

1. Parties

[REBEL7 LEGAL ENTITY — REQUIRED BEFORE EXECUTION] ("Processor") and the customer ("Controller").

2. Processing Instructions

Processor processes personal data only on documented instructions from Controller, including with regard to transfers of personal data to a third country.

3. Confidentiality

Processor ensures that persons authorized to process personal data are under an obligation of confidentiality.

4. Security Measures

AES-256 encryption at rest, TLS 1.3 in transit, RBAC, RLS-based tenant isolation, immutable audit logging, cryptographic evidence integrity. Full TOMs available in Annex.

5. Subprocessors

See Subprocessor List above. Controller is notified of changes. Right to object provided.

6. Data Subject Requests

Processor assists Controller in responding to data subject requests, taking into account the nature of the processing.

7. Breach Notification

Processor notifies Controller without undue delay after becoming aware of a personal data breach. Documentation of breaches maintained.

8. Deletion / Return

Upon termination, Processor deletes or returns all personal data after 90 days, unless law requires storage.

9. Audit Cooperation

Processor makes available information necessary to demonstrate compliance and allows audits conducted by Controller or an independent auditor.

Service Level Agreement (SLA)

AVAILABLE ON REQUEST · CONTRACT-SPECIFIC

Target Service Levels

COMMERCIAL DECISION REQUIRED

Availability target, support response times, and service credit percentages require commercial approval before commitment.

Historical Performance

No historical uptime data is published. Historical performance is not claimed. Monitoring infrastructure exists but uptime has not been formally tracked or audited.

Structure

  • Availability commitment (target: COMMERCIAL DECISION REQUIRED)
  • Support response by severity level
  • Maintenance windows (scheduled, communicated in advance)
  • Exclusions (force majeure, customer-caused issues, third-party outages)
  • Service credits (COMMERCIAL DECISION REQUIRED)
  • Incident communication process

Support Policy

AVAILABLE ON REQUEST

Support Channels

Severity Classification

  • P1 — Critical: Service unavailable or data integrity at risk
  • P2 — High: Major functionality impaired
  • P3 — Medium: Minor functionality issues
  • P4 — Low: Questions, enhancement requests

Support Hours

Monday–Friday during Italian business hours. No 24/7 or weekend support unless separately contracted.

Response Targets

OPERATIONAL DECISION REQUIRED

Specific response time targets by severity require operational decision.

Incident Response Overview

Process

  1. Detection: Log analysis, event classification, security scan workflows
  2. Triage: Severity assessment, scope determination
  3. Containment: Scope isolation, service-role containment procedures
  4. Investigation: Audit trail review, evidence chain analysis
  5. Remediation: Root cause resolution, vulnerability patching
  6. Recovery: Data restore from verified backups, service restoration
  7. Customer Communication: Affected customers notified per contractual requirements
  8. Post-Incident Review: Documentation, lessons learned, preventive measures

No 24/7 SOC. No certified SOC. Specific response times not committed. Framework evolving toward ISO-oriented standards.

Data Retention & Deletion

Documented Policy

Decision logs and audit trails are retained according to customer-configured retention policies. Upon service termination, all customer data is deleted within 90 days unless a longer retention period is required by law or requested by the customer. See Privacy Policy for details.

Automated Enforcement

NOT IMPLEMENTED

Retention is policy-based. Automated deletion enforcement is not currently implemented. Deletion is performed through a manual/process-based workflow upon request or termination.

Business Continuity & Disaster Recovery

AVAILABLE ON REQUEST · DRAFT

Verified Capabilities

  • Automated database backups via Supabase infrastructure
  • Restore capability from verified backups
  • EU-region data residency for primary data
  • Immutable audit trail and evidence chain for data integrity verification

RTO / RPO Targets

OPERATIONAL TARGET UNDER DEFINITION

Recovery Time Objective and Recovery Point Objective are under definition. No measured or approved RTO/RPO exists. No multi-region failover, hot standby, or guaranteed restore times are claimed.

Not Claimed

  • No multi-region active-active deployment
  • No hot standby infrastructure
  • No guaranteed restore time commitment

Need a document that's not listed?

Internal documents (security questionnaire foundation) are available to enterprise prospects during the vendor assessment process.