SatoriRev
Pre-launch

Security

What we can tell you, and how we know it

Each statement on this page was checked against how SatoriRev is actually configured. Where we have not checked something, it is not on this page.

Independent review · in progress

An independent security review is under way

In September 2026 we engaged an independent security consultancy, under a signed agreement, to review SatoriRev. It covers:

  • a penetration test of the SatoriRev web application and its API;
  • a read-only review of the configuration of our Amazon Web Services account.

Payments are processed by Stripe. The review does not test Stripe's own systems.

The review is not complete, and this page claims no result from it.

No certification is held, and none is claimed.

Hosting

Where it runs
The SatoriRev application and its database run on Amazon Web Services, in the US West (Oregon) region, us-west-2.

Encryption

In transit
The application is served over HTTPS. Its load balancer accepts TLS 1.2 and TLS 1.3, and redirects plain HTTP to HTTPS.
At rest
The production database is encrypted at rest, with a key held in AWS Key Management Service.

Reporting a security issue

Security contact: security@satorirev.com