New in Chargebee: Explore Reveal and understand your payment performance end-to-end.Try Now
Docschargebee docs
HomeBillingCPQPaymentsRevRecGrowthReveal
Support

Introduction


  • Overview

Transactions


  • Get Started
  • Insights
  • Understand Payment Performance
  • Alerts

Settlements


  • Get Started
  • Reconciliation
  • Fees
  • Records

Data Security


  • Data Control
  • PII Data
  • Card Vaulting
  • Data Policies, Processes and Methods

Glossary


  • Standard Terms
  1. Reveal
  2. Data Security
  3. Data Policies, Processes and Methods
  1. Reveal
  2. Data Security
  3. Data Policies, Processes and Methods

Data Policies, Processes and Methods

Reveal handles payment and settlement service data so your teams can improve authorization performance and reconcile funds with confidence. Protecting that data is part of how Reveal is operated: ownership stays with you, access is limited, and technical controls cover transit, storage, hosting, and the people who build and run the product.

This page summarizes Reveal’s security policies and methods. For what Reveal can ingest and delete, see Data control. For personal data choices, see PII data. For cardholder-data context, see Card vaulting.

Key considerations

Data access and ownership

Your Reveal data remains your property. Chargebee Reveal does not access your merchant data without a legitimate need, such as support you request, security investigation, or quality assurance related to the service. Routine product use does not grant other customers access to your data.

Data privacy

Reveal does not sell your data. Before Reveal permanently deletes account data as part of offboarding or a purge you request, you should have time to export what you need for your own records. See Data control.

Data encryption

Reveal encrypts service data in transit using TLS, and encrypts data at rest using Amazon Key Management Service (KMS) for production data stores and related production disks.

Certified hosting partners

Reveal is hosted with leading cloud data center providers. Access to those facilities is controlled by the provider. Hosting partners maintain certifications such as SOC 2 Type 2 and ISO 27001, and design for redundant power, network, and environmental services.

Penetration testing

Reveal relies on recurring third-party assessments (including network and application testing) and internal reviews to find and fix security issues.

Cloud security

Physical security of data centers

Reveal uses cloud provider data centers that meet industry physical security standards for personnel, perimeter, monitoring, and intrusion detection.

Facility certifications

Reveal primarily runs on AWS. AWS data centers support certifications such as ISO 27001, PCI DSS, and SOC 2 for services used to host service data. Independent physical security reviews are part of those compliance programs.

Location of data hosting

Reveal uses AWS regions that can include the United States, Europe, India, and other regions so storage and processing can align with applicable requirements for payment-related service data. Work with Chargebee on the hosting location that applies to your Reveal account when regional placement matters for your compliance program.

Network security

Dedicated information security team

Chargebee maintains an information security function that monitors for security alerts and incidents affecting services such as Reveal.

Network firewalls

Reveal’s network path is protected with network-level firewalling. Firewall rules are monitored and controlled to limit exposure to network attacks.

External testing and monitoring

In addition to internal scanning, Reveal’s security program uses recurring third-party assessments. Production defenses also use AWS security services and operational monitoring to detect and block known malicious traffic.

Key encryption

Encryption in transit

Data sessions between clients and Reveal services use TLS.

Encryption at rest

Production databases and disks used by production application servers are encrypted at rest with Amazon KMS.

Application security practices

Third-party penetration testing

Application and related assessments run on a recurring schedule throughout the year.

Secure development

Engineers receive secure code training that covers common risks (including OWASP Top 10 themes), attack patterns, and Chargebee security controls. Test and staging environments are separated from production and do not use production service data.

Security policies and awareness

Security policies apply to employees and contractors who can access Chargebee resources. Security awareness training is part of onboarding and is refreshed periodically. Engineers also receive ongoing secure-coding refreshers. Background checks for new employees follow local regulations and auditor requirements where applicable.

Take the next step

  • Data control: Ingestion boundaries and deletion.
  • PII data: Personal data permissions in Reveal.
  • Card vaulting: Cardholder data and PCI context.
  • Chargebee security: Broader Chargebee security and compliance materials.

See also

  • Reveal overview
  • Chargebee PCI DSS

Was this article helpful?