Document Inventory
Privacy Policy
Describes data collection, usage, storage, retention, and user rights.
Exists in Legal.jsx. Updated to correct SOC 2 and penetration testing claims.
Terms of Service
Governs access to and use of the Rebel7 AI Governance Engine.
Exists in Legal.jsx.
Security Overview
Architecture, access control, encryption, evidence integrity, and compliance alignment.
Exists as Security.jsx. Claims verified against implementation.
Trust Center
Public attestation repository with evidence integrity gate.
Exists as Rebel7TrustCenter.jsx. Procurement Center links from here.
Technology Proof
Live cryptographic evidence chain demonstration with tamper detection.
Exists as TechnologyProof.jsx. Demo data clearly marked.
Subprocessor List
List of third-party providers that process customer data.
Built from verified infrastructure. Some regions/transfer mechanisms require verification.
Data Processing Addendum (DPA)
Data processing agreement template for enterprise customers.
DRAFT — NOT FOR EXECUTION. Future S.r.l. not yet incorporated. Founder currently operates through individual Italian VAT position. Legal entity placeholder [REBEL7 LEGAL ENTITY — REQUIRED BEFORE EXECUTION] must be resolved before signing.
Service Level Agreement (SLA)
Enterprise SLA draft with target service levels. Contract-specific.
No historical uptime claimed. SLA targets marked as COMMERCIAL DECISION REQUIRED. Service credits require commercial approval.
Support Policy
Support channels, severity classification, and escalation process.
Support hours: Monday–Friday during Italian business hours. No 24/7 or weekend support. Response targets require operational decision.
Incident Response Overview
Enterprise-facing incident response process overview.
Based on existing Security.jsx architecture. No 24/7 SOC or certified SOC claim. Specific response times not committed.
Data Retention & Deletion Policy
Documented retention and deletion behavior.
Policy exists in Legal.jsx. Automated enforcement not implemented — deletion is manual/process-based.
Business Continuity & Disaster Recovery
BCP/DR draft based on verified infrastructure capabilities.
RTO/RPO under definition — OPERATIONAL TARGET UNDER DEFINITION. No multi-region failover, hot standby, or guaranteed restore times claimed.
Security Questionnaire Foundation
Internal reusable enterprise security questionnaire knowledge base.
Internal sales enablement document. Not shared externally. Some items require verification.
Subprocessor List
The following third-party providers process customer data as part of operating the Rebel7 platform. Entries marked "TO VERIFY" require confirmation of processing region or transfer mechanism.
| Provider | Classification | Purpose | Data Category | Region | Privacy/DPA |
|---|---|---|---|---|---|
| Base44 | CONFIRMED CUSTOMER-DATA SUBPROCESSOR | Application hosting platform, backend-as-a-service, build and deployment infrastructure | Application source code, environment variables, deployment metadata. Does not directly process end-user personal data. | TO VERIFY | Link ↗ |
| Supabase | CONFIRMED CUSTOMER-DATA SUBPROCESSOR | PostgreSQL database, authentication, file storage, edge functions | User authentication data, organization records, application data, file uploads | EU (configured) | Link ↗ |
| Stripe | CONFIRMED CUSTOMER-DATA SUBPROCESSOR | Payment processing, subscription billing, invoicing | Payment method tokens, billing address, transaction records. Rebel7 does not store raw card data. | TO VERIFY | Link ↗ |
| Resend | CONFIRMED CUSTOMER-DATA SUBPROCESSOR | Transactional email delivery (trial notifications, sales sequences, whitepaper delivery) | Email addresses, email content, delivery metadata | TO VERIFY | Link ↗ |
| OpenAI | CONDITIONAL / DEPENDS ON FEATURE | AI model inference for InvokeLLM integration (optional model selection) | Text prompts and generated responses passed through the AI Gateway. No training on customer data. | TO VERIFY | Link ↗ |
| Anthropic | CONDITIONAL / DEPENDS ON FEATURE | AI model inference for InvokeLLM integration (optional model selection) | Text prompts and generated responses passed through the AI Gateway. No training on customer data. | TO VERIFY | Link ↗ |
| CONDITIONAL / DEPENDS ON FEATURE | OAuth authentication provider (Google Sign-In) | Email address, name, profile picture for users who choose Google authentication | TO VERIFY | Link ↗ | |
| GitHub | DEVELOPMENT TOOL ONLY | Source code hosting, version control, CI/CD (development tooling) | Source code, commit metadata. Does not process end-user personal data. | TO VERIFY | Link ↗ |
| DocuSign | CONDITIONAL / DEPENDS ON FEATURE | Electronic signature for compliance documents (optional Comply module) | Signer name, email, signature records for documents sent through Comply module | TO VERIFY | Link ↗ |
Data Processing Addendum (DPA)
This DPA template is provided for review purposes only. The future S.r.l. has not yet been incorporated; the founder currently operates through an individual Italian VAT position. The legal entity placeholder [REBEL7 LEGAL ENTITY — REQUIRED BEFORE EXECUTION] must be resolved before signing. Contactenterprise@rebel7.ai to request the executable version.
1. Parties
[REBEL7 LEGAL ENTITY — REQUIRED BEFORE EXECUTION] ("Processor") and the customer ("Controller").
2. Processing Instructions
Processor processes personal data only on documented instructions from Controller, including with regard to transfers of personal data to a third country.
3. Confidentiality
Processor ensures that persons authorized to process personal data are under an obligation of confidentiality.
4. Security Measures
AES-256 encryption at rest, TLS 1.3 in transit, RBAC, RLS-based tenant isolation, immutable audit logging, cryptographic evidence integrity. Full TOMs available in Annex.
5. Subprocessors
See Subprocessor List above. Controller is notified of changes. Right to object provided.
6. Data Subject Requests
Processor assists Controller in responding to data subject requests, taking into account the nature of the processing.
7. Breach Notification
Processor notifies Controller without undue delay after becoming aware of a personal data breach. Documentation of breaches maintained.
8. Deletion / Return
Upon termination, Processor deletes or returns all personal data after 90 days, unless law requires storage.
9. Audit Cooperation
Processor makes available information necessary to demonstrate compliance and allows audits conducted by Controller or an independent auditor.
Service Level Agreement (SLA)
Target Service Levels
COMMERCIAL DECISION REQUIRED
Availability target, support response times, and service credit percentages require commercial approval before commitment.
Historical Performance
No historical uptime data is published. Historical performance is not claimed. Monitoring infrastructure exists but uptime has not been formally tracked or audited.
Structure
- Availability commitment (target: COMMERCIAL DECISION REQUIRED)
- Support response by severity level
- Maintenance windows (scheduled, communicated in advance)
- Exclusions (force majeure, customer-caused issues, third-party outages)
- Service credits (COMMERCIAL DECISION REQUIRED)
- Incident communication process
Support Policy
Support Channels
- General: info@rebel7.ai
- Enterprise: enterprise@rebel7.ai
- Security: security@rebel7.ai
- Privacy: privacy@rebel7.ai
Severity Classification
- P1 — Critical: Service unavailable or data integrity at risk
- P2 — High: Major functionality impaired
- P3 — Medium: Minor functionality issues
- P4 — Low: Questions, enhancement requests
Support Hours
Monday–Friday during Italian business hours. No 24/7 or weekend support unless separately contracted.
Response Targets
OPERATIONAL DECISION REQUIRED
Specific response time targets by severity require operational decision.
Incident Response Overview
Process
- Detection: Log analysis, event classification, security scan workflows
- Triage: Severity assessment, scope determination
- Containment: Scope isolation, service-role containment procedures
- Investigation: Audit trail review, evidence chain analysis
- Remediation: Root cause resolution, vulnerability patching
- Recovery: Data restore from verified backups, service restoration
- Customer Communication: Affected customers notified per contractual requirements
- Post-Incident Review: Documentation, lessons learned, preventive measures
No 24/7 SOC. No certified SOC. Specific response times not committed. Framework evolving toward ISO-oriented standards.
Data Retention & Deletion
Documented Policy
Decision logs and audit trails are retained according to customer-configured retention policies. Upon service termination, all customer data is deleted within 90 days unless a longer retention period is required by law or requested by the customer. See Privacy Policy for details.
Automated Enforcement
NOT IMPLEMENTED
Retention is policy-based. Automated deletion enforcement is not currently implemented. Deletion is performed through a manual/process-based workflow upon request or termination.
Business Continuity & Disaster Recovery
Verified Capabilities
- Automated database backups via Supabase infrastructure
- Restore capability from verified backups
- EU-region data residency for primary data
- Immutable audit trail and evidence chain for data integrity verification
RTO / RPO Targets
OPERATIONAL TARGET UNDER DEFINITION
Recovery Time Objective and Recovery Point Objective are under definition. No measured or approved RTO/RPO exists. No multi-region failover, hot standby, or guaranteed restore times are claimed.
Not Claimed
- No multi-region active-active deployment
- No hot standby infrastructure
- No guaranteed restore time commitment
Need a document that's not listed?
Internal documents (security questionnaire foundation) are available to enterprise prospects during the vendor assessment process.