Designed for careful pricing operations.
Credential boundaries, explicit permissions, and reviewable changes form the security model for RevenueStack.
This page describes the intended security model. Deployment-specific implementation evidence and policies must be confirmed with the RevenueStack team. No certification, audit result, or uptime guarantee is asserted here.
Encrypted stored credentials
Platform credentials are intended to be encrypted at rest and handled by server-side services. Credentials should never be embedded in marketing pages or browser bundles.
Server-side credential handling
Sensitive platform operations belong on the server. Browser interfaces should receive the information needed for review without exposing underlying secrets.
Restricted service-role credentials
Privileged service credentials should remain restricted to trusted server processes. They are not workspace API keys and should not be distributed to end users or agents.
Workspace isolation
Platform connections and pricing records should be scoped to their workspace. Access should be checked against the requesting user or tool key.
Permissioned MCP keys
Agent keys should carry only the permissions needed for the task. Review access regularly and revoke unused or exposed keys.
Approval safeguards
Sensitive deployment operations follow approval settings. A preview or an agent recommendation is not, by itself, an approved live change.
Audit trails
Pricing history records the actor, proposed and applied changes, status, and platform response so teams can investigate outcomes.
Protected subscriptions
Protected subscriptions and excluded territories keep designated prices outside a proposed deployment. Review the exclusions alongside each dry run.
Secret masking
Credential fields and diagnostic output should mask secrets. Avoid placing tokens in screenshots, support messages, logs, or agent conversations.
Build a global pricing strategy
you can actually operate.
Connect your subscription platforms and review your first regional pricing plan.