How we protect your work and govern AI, without promises we cannot support.
Infrastructure and data residency
We run on Cloudflare: Workers, D1 database and R2 storage. The relational database is in Western Europe and PDFs are in a bucket with EU jurisdiction. Your data is stored in the EU. AI processing is performed by our US-based AI providers under GDPR Standard Contractual Clauses.
Encryption
All communications are encrypted in transit with HTTPS/TLS, and platform storage is encrypted at rest.
Authentication and access
Passwords use PBKDF2 hashing with a per-user salt and are never stored as plain text. Sessions use cookies. Customer data is isolated: each project belongs to its owner and files are stored by project.
Traceability and audit
The audit log is append-only: actions cannot be changed or deleted. Screening decision history is immutable, so every decision can be reconstructed for a reproducible methods appendix.
AI governance
AI suggests; you decide. Screening and extraction are drafts that a human reviewer confirms or corrects, a supervised-draft approach, and the human decision always prevails. Prompts are validated against reference reviews (pooled safety sensitivity 99,4%; see Methodology). Each project has an AI budget to control usage, and every call is logged. Under our AI providers' commercial terms, content sent through their commercial APIs is not used to train models.
Privacy
We comply with the GDPR. See Privacy and Terms of Use. For an institutional data processing agreement, email equipo@revisia.es.
Reproducibility
Search strategies are stored as immutable, versioned records and can be exported. The PRISMA 2020 diagram is derived from the project's real state. Methodological transparency is part of the product.
What we do not do
We do not sell your data. We do not use your projects to train models. We do not make inclusion decisions for you: the tool assists and the review team decides.
Last updated: 2026-06-16