Questions Clients Have Asked
This page answers real due diligence questions clients and prospects have asked about Sales Triage, Revenue Engine, AI, security and data protection.
If one client has asked a useful question, future clients should not have to ask it again.
Where is Revenue Engine hosted?
Revenue Engine is currently hosted on a UK virtual server with Fasthosts.
During beta, the web application and database are hosted on the same virtual server.
Where is client data stored?
Data stored directly in the Revenue Engine platform is currently stored in the UK.
Some third-party services, such as AI providers, may process data outside the UK depending on the feature being used.
Are you a data processor, and do you have an Article 28 agreement?
For client platform data, yes.
Where your organisation stores contacts, prospects, notes, activities, opportunities or emails in the platform, your organisation is the data controller and Sales Triage is the data processor acting on your instructions. Our Data Processing Terms, set out in our Terms and Conditions, are intended to operate as the UK GDPR Article 28 data processing agreement and cover our obligations as processor (security measures, approved subprocessors, assistance with data subject requests, breach notification, and return or deletion of data).
The account-level and usage data we generate to run the service (account administration, billing, security and operational logs) is processed by Sales Triage as a controller. The Privacy Policy explains this split in full.
Is data encrypted in transit?
Yes.
Traffic to the platform is protected using HTTPS/TLS.
Is data encrypted at rest?
Partly, and we are precise about which parts.
Stored API credentials and integration secrets (such as third-party API keys and webhook secrets) are encrypted at rest using AES-256-GCM. Stored OAuth tokens for connected mailboxes and calendars are also encrypted at the field level using AES-256-GCM.
The application database is not yet protected by full-database (volume-level) encryption at rest. That is a planned improvement before wider production use.
If file or document storage becomes a broader part of the service, encryption at rest will be included in the production security plan.
Do you have multi-factor authentication?
Yes. Multi-factor authentication is enabled for every platform user and is required at sign-in, including for administrators.
After their password, each user completes a second step with an authenticator app (for example Authy, Google Authenticator or Microsoft Authenticator) or a one-time code sent to their registered email address. Users cannot disable it on their own account.
Who has access to production systems?
During beta, production access is limited to the founder.
Within one account, can different users see each other's data?
Partly, and it depends on the record and the user's role.
Each client organisation is a separate tenant, and no organisation can see another organisation's data. Inside one organisation there are two roles. An organisation administrator can see and manage all of that organisation's records. A standard user has full access to the records they own and a limited card-only view of colleagues' contacts and companies - name, job title, email, phone and who owns the record - while the deeper detail (activity timeline, opportunities, pain analysis, notes and analytics) stays private to the owner and administrators. Coaching relationships and their notes are more restricted again: they are visible only to the owning coach and the coachee.
These rules are enforced in the data layer beneath the interface, not only by hiding things on screen, and both reads and writes are checked against the viewer's role and the record's ownership.
A manager who needs to see everything their team is doing is given the organisation administrator role, which already provides visibility of all records in the organisation. More granular team or territory controls (for example a user restricted to their own pipeline while a manager sees a defined subset of colleagues) are not currently implemented and will be considered based on demand.
Do AI features respect who can see what?
They respect the organisation boundary, and currently work at organisation scope inside it.
AI features never cross between organisations. Inside one organisation, when an AI feature summarises a meeting or drafts a follow-up, it builds its working context from the records linked to that meeting across the organisation. Because contact and company cards are already shared across the organisation, a summary of a meeting you ran can reference a linked opportunity owned by a colleague in the same organisation. We do not currently narrow the AI's working context to only the individual user's own records within their organisation, and we would rather state that plainly than imply a per-user AI boundary that is not in place.
Do you have separate development, staging and production environments?
Not yet.
Revenue Engine is currently operating with production only during beta.
A separate staging environment is planned before wider production use.
How are backups handled?
During beta, Revenue Engine uses weekly full backups and daily incremental backups.
Backups are held on the server and also copied offsite to UK-hosted Microsoft OneDrive.
Backup retention and restore testing are being formalised as part of the improvement plan.
Have you tested restoring from backup?
A formal restore test has not yet been completed and documented.
This is a priority improvement.
How quickly could you recover the service if the server failed?
During beta, the realistic recovery target is within 24 hours.
This is a practical recovery target, not a formal uptime SLA.
Are you ISO 27001 certified?
No.
Sales Triage is not currently ISO 27001 certified.
We are familiar with ISO 27001 and have experience operating businesses with security certifications, but the current Sales Triage entity does not hold ISO 27001 certification.
Are you SOC 2 certified?
No.
Sales Triage is not currently SOC 2 certified.
Do you have Cyber Essentials?
No.
Cyber Essentials is under review as a proportionate next step.
Have you completed penetration testing?
No independent penetration test has been completed yet.
Independent testing is planned before accepting larger enterprise clients or before wider production use.
Is client data used to train AI models?
No.
Client content submitted through Revenue Engine AI features is not used to train AI models under the commercial API services used by Sales Triage.
Which AI providers do you use?
The AI providers currently in use are Anthropic and OpenAI.
The provider used may vary by feature and may change as the service evolves. If we engage a new AI provider, it is added to the supplier and subprocessor list, and we route personal data to it only once it is engaged under an appropriate data processing agreement.
Can AI providers process data outside the UK?
Yes.
AI providers may process data outside the UK, including in the United States.
Where international transfers occur, Sales Triage relies on appropriate contractual safeguards where required.
Where are video messages stored?
Video messages recorded in the platform are hosted and streamed by a specialist video provider rather than on the application server.
The video and audio you record, along with the video title and thumbnail, are processed by that provider to host and play back the message. The provider is listed on the Suppliers and Subprocessors page.
Does the platform record and transcribe meetings?
Where it is enabled, a meeting notetaker can join your online video meetings (for example Zoom, Microsoft Teams, or Google Meet) to capture an audio recording and produce a written transcript. Video is not recorded.
The notetaker joins as a visible participant with a name that shows a notetaker is present (for example "[Name]'s Notetaker (powered by Sales Triage)"), so it is not hidden from attendees. The host chooses whether to record, and can choose not to.
The transcript is stored against the meeting record and is processed by our AI providers (see AI and Data Processing) to produce summaries and follow-up actions. The audio recording is held by our meeting provider (Nylas) behind time-limited links; we do not keep the audio file on our own servers.
A recording and transcript capture what everyone on the call says, including people who are not platform users. Where Sales Triage hosts the meeting, we are the controller and rely on legitimate interests, and attendees can object. Where one of our clients hosts the meeting, that client is the controller and is responsible for informing their own attendees; Sales Triage acts as the processor. The Privacy Policy explains this in full.
Does Revenue Engine read my whole mailbox?
No.
Where email functionality is enabled, Revenue Engine connects to the user's chosen mailbox for the functionality authorised by the user.
The platform does not operate as a separate bulk sending service and does not monitor general mailbox content outside authorised functionality.
How would you know if there was a breach?
A fair question, and we answer it honestly rather than claiming a full monitoring suite we do not have.
The platform keeps a login and access audit trail: successful sign-ins, sign-outs, and failed sign-in attempts are recorded, along with any tenant boundary violation (an attempt by one organisation's session to reach another organisation's data - something that should never happen in normal use). A tenant boundary violation sends an alert email to our operator so it is seen promptly. Sign-in is also protected against brute-force attacks, with repeated failed attempts rate-limited and locked out, and the operator alerted to sustained attacks.
What we do not yet have is a fully automated, centralised intrusion-detection system across the whole environment. Our alerting today is targeted at specific high-signal events rather than general anomaly detection, and broader monitoring is on the Continuous Improvement plan. Alongside our own logging, we also rely on alerts from the providers and infrastructure we use.
What happens if you discover a data breach?
Sales Triage will investigate, contain and assess the incident.
Where client data is affected, Sales Triage will notify affected clients where required by law or contract and support clients with any related regulatory obligations.
Sales Triage will follow UK GDPR breach notification requirements.
Can clients export their data?
Yes, with our help today.
Our terms provide for client platform data to be exportable around termination (the Privacy Policy describes a 30-day window) and then deleted. Today this is handled manually on request: we will produce and return a copy of the client's platform data. A self-serve export is a priority improvement and is on the Continuous Improvement plan; we would rather say that plainly than imply a one-click export that is not built yet.
What happens if a client leaves Sales Triage?
Client platform data is handled in line with the applicable terms and data processing terms.
In practice today, on termination we will return a copy of the client's platform data on request and then delete it. We are formalising this into a documented, time-bound process - a self-serve export followed by an automated deletion step - as a priority improvement (see Continuous Improvement).
How is my data deleted if we decide not to proceed?
If you decide not to continue, we will delete your platform data and confirm once it is done.
Today that deletion is carried out manually by the founder on request rather than by an automated, time-bound process. A documented, automated deletion process (with a self-serve export available beforehand) is a priority improvement. Copies held in backups age out on the normal backup rotation rather than being individually removed.
What happens to my data if Sales Triage winds down?
You would be able to obtain a copy of your platform data so you can move it to another system.
This is a fair question for any small supplier, and we would rather answer it directly. The platform data you store is yours; if we wound the service down, we would make your data available for export and then delete it. As above, export is founder-assisted today, with a self-serve export on the improvement plan.
Do you sell personal data?
No.
Sales Triage does not sell personal data.
Do you process special category data?
Revenue Engine is not intended to process special category data.
Users should not submit special category data unless this has been expressly agreed in writing.
What should happen when a new question is asked?
If a client asks a new security, privacy or AI question:
- answer the client directly
- add the question here if it is useful to future clients
- update the relevant page if the answer changes public documentation
- add an improvement item if the question exposes a gap
- add a changelog entry if public documentation changes