Last updated 1 August 2026
Read our Privacy Policy →This page is maintained by the Recover AI team to answer common security questions about the platform. It describes the controls we currently operate — it is not an independent audit, certification or attestation.
Recover AI never receives, stores or moves funds, and we do not handle full card numbers, CVV codes or bank credentials. Payment method updates happen on your own payment processor's hosted checkout, reached through a Recover AI magic link.
All traffic to the application is served over HTTPS/TLS. Data at rest is encrypted by our managed infrastructure providers.
Every merchant-facing table is protected by row-level security scoped to the signed-in account, so one merchant cannot read or modify another merchant's data. Privileged database routines are restricted to server-side service roles and are not callable by end users. Administrative access within our team is limited to the people who need it to operate the service.
Recovery links are single-purpose tokens tied to one invoice, expire 14 days after creation, and carry no account credentials. Opening a link does not sign anyone into a dashboard.
API keys and provider credentials are held in a managed secret store, injected at runtime, and are never exposed to the browser. Outbound messaging runs through Twilio, and email through our hosting provider's delivery infrastructure.
We secure the platform, its infrastructure and tenant isolation. As a merchant, you are responsible for keeping your account credentials safe, for the lawfulness of the customer data you upload, and for who you invite into your account. Your customers are responsible only for completing checkout on your processor's page.
If you believe you have found a security issue, email security@recover-ai.tools with steps to reproduce. We aim to acknowledge reports within two business days. Please do not publicly disclose an issue before we have had a chance to respond, and do not access data that is not yours while testing.
If a security incident affects your data, we will notify affected merchants by email without undue delay, with what we know and what we are doing about it.
We do not claim SOC 2, ISO 27001, PCI DSS or HIPAA compliance. Where those frameworks matter to your purchase, contact us and we will tell you exactly what we can and cannot support today.