Skip to content

Security

Dunning software security built on least privilege

Secure dunning software needs only the billing access recovery requires, keeps that access encrypted and records every action. RevRescue connects with a least-privilege restricted key encrypted at rest, writes all actions to an audit log, offers admin, operator and viewer roles, keeps SMS consent records and deletes your key when you disconnect.

Finance director and security lead reviewing access settings on a laptop

Restricted keys instead of full account access

Payment recovery does not need the power to move money out of your account, create payouts or change bank details, so RevRescue never asks for it. On your billing platform you create a restricted key with the specific read and write permissions recovery uses, for example reading customers, subscriptions, invoices and charges, and retrying invoice payments. The setup screen lists each permission and why it is needed, and setup takes about ten minutes.

Keys are encrypted at rest and decrypted only inside the process that calls your billing platform. They are never shown again after you save them, never written to logs and never sent to the browser. The same principle applies to Chargebee, Paddle, Shopify and the CRM connections for HubSpot, Salesforce and Pipedrive: the narrowest scope the integration allows.

Restricted keys instead of full account access
Permission area Access Why
Customers and subscriptions Read Know who to contact and what they pay
Invoices and charges Read and retry See failures and run timed retries
Payment methods Read expiry only Send reminders before a card expires
Payouts, balance, bank accounts None Not needed for recovery
Prices and coupons Read Leak Scan comparisons, changes only after your approval

Roles and an audit log for every action

Each team member gets one of three roles. Admins manage connections, billing, sequences and users. Operators run recovery, approve hand-offs, record promises to pay and act on Leak Scan findings. Viewers see dashboards and account lists without changing anything. Enterprise adds single sign-on and custom roles, so you can, for example, let support see accounts but not edit message templates.

The audit log records who did what and when: connections added or removed, sequences edited, messages sent, retries triggered, findings accepted, roles changed and data exported. Entries cannot be edited from the product and can be exported for your own review.

  • Admin, operator and viewer roles on every plan.
  • SSO and custom roles on Enterprise.
  • Audit log with export on every plan.
  • Only admins can add or remove connections and change roles.

Data minimization and customer messaging

RevRescue stores only what recovery needs: customer identifiers, contact details, subscription and invoice records, decline codes and the history of messages and actions. Full card numbers never reach RevRescue, because card updates happen on the payment page of your billing platform. Card data stays with the payment provider.

Messages are sent on your behalf to your own customers. SMS goes only to customers who gave consent, and RevRescue keeps a consent record for each number, including when and how consent was given. Every SMS includes an opt-out, and opt-outs are honored across all sequences immediately. Email sequences include an unsubscribe link for non-transactional messages such as win-back.

Where data is handled and how disconnect works

Data is processed in infrastructure located in the EU and the US, with access limited to staff who need it to run the service. Data is encrypted in transit and at rest. Enterprise customers can sign a data processing agreement covering processing terms, subprocessor categories and security measures.

When you disconnect a billing platform, the stored key is deleted at once and RevRescue stops all calls to that account. When you close your RevRescue account, customer data is deleted after a short retention window that lets you reverse an accidental closure. Requests about your data go to [email protected].

  1. 1

    Disconnect in settings

    An admin removes the connection. The key is deleted and active sequences for that account stop.

  2. 2

    Revoke on your side

    Delete the restricted key in your billing platform as well, so access ends on both sides.

  3. 3

    Export if needed

    Download recovery history and the audit log before closing your account.

Security questions we answer plainly

RevRescue does not claim SOC 2 or ISO 27001 certification. What we offer is a narrow access model, encryption, a complete audit trail and clear deletion. If your review needs a questionnaire answered, send it to [email protected]. For how keys are used in practice, see the billing integration guide, and for plan features see pricing.

Frequently asked questions

Is it safe to give dunning software access to your billing platform?

It is safer with a restricted key that grants only the permissions recovery needs and no access to payouts or bank details. RevRescue uses exactly that model and encrypts the key at rest.

Does RevRescue store card numbers?

No. Customers update cards on the payment page of your billing platform, so card data stays with the payment provider. RevRescue only reads card expiry to send reminders.

Is RevRescue SOC 2 certified?

No. RevRescue does not hold SOC 2 or ISO 27001 certification. We describe our actual controls, including restricted keys, encryption, roles and audit logging.

What happens to my data when I disconnect?

The stored key is deleted immediately and all calls to that billing account stop. Closing your account deletes customer data after a short retention window.

Can we sign a data processing agreement?

Yes, a DPA is available on the Enterprise plan, together with SSO and custom roles.

Connect with a restricted key in about ten minutes

Enter your MRR and failed payment rate. The estimate takes under a minute and needs no signup.

Find my lost revenue