Reveal
Reveal provides hosted Review and disclosure technology powered by AI. Clients can upload data for litigation, regularity response or any other legal issue where eDiscovery or investigation needs to happen with large amounts of data.
Features
- Reveal offers Advanced Searching with Boolean and Concept Capabilities.
- Reveal provides Real-Time Result Counts for Efficient Searching Process.
- Reveal features Thumbnail Preview for Visual Document Insight Always.
- Reveal supports Bulk Rendering of Native Files to PDF.
- Reveal has Field-Specific Search Options for Precise Data Retrieval.
- Reveal offers Interactive Data Visualizations for Quick Insights Always.
- Reveal provides Custom AI Models for Specific Investigations Easily.
- Reveal features Generative AI for Natural Language Queries
- Reveal offers Predictive Coding and Active Learning Technology.
- Reveal supports Automated First Pass Tagging using GenAI Technology.
Benefits
- Advanced AI capabilities for efficient data analysis and review.
- Intuitive interface for seamless user experience and navigation
- Powerful tools for predictive coding and document prioritization
- Customizable AI models for specific investigation types and cases
- Compliance and risk analysis for potential policy violations detected.
- Informed data decisions for categorization and data organisation
- Transparent and predictable pricing structure with no hidden fees.
- Unlimited users and access to all platform components included.
- World-class security measures for data protection and safety ensured.
- 24/7 customer support and dedicated success manager assigned.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 8 3 9 1 8 2 9 8 0 7 9 3 1
Contact
REVEAL BRAINSPACE LIMITED
Samantha Mather
Telephone: 07951271978
Email: smather@revealdata.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI software services
- Generative AI Software Services
- Document AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- N/A
- System requirements
- Web browser as system is SaaS
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 15 mins
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- We provide 24 x 7 x 365 support. Our global Support Engineers continue to work on all support tickets and provide recommendations for resolution if beyond the Customer's working hours. We provide multiple support channels, consisting of online access to the Reveal Support Portal, email, telephone, and a knowledge database. In addition, your allocated Customer Success Manager can assist with the logistics of Support tickets and any escalations needed due to shortened timeframes outside of the SLAs. We pride ourselves on our Support, and where possible, once the Support ticket is logged, we will organize a screen share and/or speak with the Customer team directly via telephone. Although we take ownership of all support tickets and SLAs, the knowledge database with our Support Portal provides self-diagnostics and the opportunity for our staff to resolve the issue themselves.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Reveal offers both consultant lead training as well as full online training. There is also award winning user documentation.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users can download or produce their data before the contract ends.
- End-of-contract process
- All data and the instance is destroyed after the contract end date unless extended
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our Administration and User guides are updated regularly and can be accessed directly from a web browser at https://www.Revealdata.com/documentation, or within the Reveal SaaS platform.
Database and installation documentation will be provided by the Customer Success Management team, together with appropriate face-to-face training or consulting to ensure the documentation being provided is understood and meets expectations.
In addition, up-to-date documentation for product releases can be accessed directly from a web browser at https://www.Revealdata.com/documentation, or within the Reveal SaaS Platform.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Reveal offers a full open API documentation where developers can perform actions within the tool using these APIs. A full list of APIs can be provided.
https://review-help.revealdata.com/en/Reveal-AI-Integration-API.html - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
-
We make commercially reasonable efforts to provide notice of scheduled maintenance that may materially affect the access and use of the Service at least twenty-four hours in advance.
We also make commercially reasonable efforts to promptly notify Customers of any known period of unavailability and a further notice when the Service disruption has ended.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Yes, we provide usage metrics to all our customers from within the application.
Usage metrics include information on how much is stored and how much is associated to each data source. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
We encrypt data at rest using AES-256 encryption protocols for both databases and files.
Data at rest is encrypted with a combination of S3 KMS encryption and volume-level encryption which both make use of AES.
Hosted data is encrypted at rest using AES-256 encryption protocols for both databases and files. - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Using our production module, users can export data
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Concordance
- Native files
- Text files
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Native files
- Metadata load files
- Forensic images
- Image load files
- Text files
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
We encrypt data in transit over untrusted networks, such as the public Internet.
Data in transit is encrypted via TLS 1.2 or above.
Data in motion is encrypted with SSL using only strong protocols and ciphers.
Client data in transit over untrusted networks is encrypted.
We encrypt data in transit into and out of our production environment using TLS 1.2. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
We encrypt data in transit over untrusted networks, such as the public Internet, via TLS 1.2 or above.
Data in motion is encrypted with SSL using only strong protocols and ciphers.
Client data at rest is encrypted using open-source and industry-standard technologies, including Transport Layer Security (TLS), Secure Shell/Secure FTP (SSH/SFTP), and Advanced Encryption Standard (AES).
Availability and resilience
- Guaranteed availability
-
We guarantee system availability of 99.82% and above, with some statements confirming an availability percentage of no less than 99.95%.
All client data are stored at Tier III+ data centers that guarantee 99.982% uptime.
The Services will be available at least 99% of the time, as measured on a per-minute basis every month. - Approach to resilience
-
We manage system resilience through a combination of failover strategies, disaster recovery RPO/RTO targets, and geographic redundancy.
Our SaaS application runs on AWS, which supports 99.982% uptime, and we maintain an Availability Percentage of no less than 99.95%.
Primary data sources such as databases, indexes, and file artifacts are snapshotted into AWS S3 for replication and high-level durability guarantees.
We utilize AWS and multiple availability zones to ensure resilience and high availability, with normal operations distributed across data centers with cluster technologies to mitigate the impact of a single data center loss.
Our disaster recovery and business continuity plans include replicating data and services to multiple availability zones within a region and a formal framework by which an unplanned event will be managed to minimize the loss of vital resources. - Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
We incorporate Role-Based Access Control (RBAC), a fundamental security feature that grants organizations the ability to manage and restrict user permissions within the interface.
RBAC ensures that users are granted appropriate access based on their roles and responsibilities within the organization.
With RBAC, organizations can control who can view, edit, create, delete, or manage different aspects of the Reveal platform.
RBAC follows the principle of least privilege, ensuring that users are granted only the minimum permissions necessary to perform their tasks. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We have established a comprehensive approach to guarding against cybersecurity risks.
Our documented information security policies are based on industry-standard controls such as ISO27001, SOC 2 Type II, and NIST 800-53, overseen by our Chief Information Security Officer (CISO) in collaboration with the Information Security Steering Committee, senior management, and the DevSecOps team.
We conduct annual third-party penetration testing, vulnerability assessments, and application testing on all environments, with additional internal vulnerability assessments performed weekly.
Security is integrated into our Software Development Life Cycle (SDLC) through third-party static and dynamic scanning tools.
We also undergo a comprehensive SOC2 Type II audit to evaluate the effectiveness of our internal controls and security measures.
Our risk management system ensures that information security risks and incidents are reported to senior management.
We maintain cyber security insurance to further mitigate risk.
All policies are reviewed at least every 12 months and deviations require approval from the CISO and Information Security Steering Committee.
Our SOC 2, ISO and Pen Test documentation can be found herehttps://security.revealdata.com/ - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We establish, document, approve, communicate, apply, evaluate, and maintain policies and procedures for managing risks associated with changes to organizational assets.
Our Change Management Team collaborates with customers to coordinate upgrade cycles, and our SaaS environment undergoes monthly updates with pre-release software available in a User Acceptance Testing (UAT) environment. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We have a formal, documented vulnerability policy that requires assessments of all systems, applications, and networks that store client data.
Our policy has been independently verified through an audit or external assessment group.
We conduct third-party penetration testing, vulnerability assessments, and application testing annually across all environments.
We have established formal policies and procedures for patching servers, workstations, applications, and network devices. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We have Access Logs available to administrators that contain a variety of actions that are logged including: Access, Add, Delete, Edit, Manage, Rename, Sync, Update and View.
These actions are logged by date, time, user and IP address. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We have a documented incident response plan that includes procedures for reporting incidents and notifying clients in the event of a breach.
The plan describes the overall approach for responding to information security incidents, including detecting and reacting to incidents, determining their scope and risk, responding appropriately, and communicating results and risk to stakeholders. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- For a 30 day period, buyers can conduct a POV with either test or their own data within a full environment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 25%
- Between £250,000 and £500,000
- 25%
- Between £500,001 and £1,000,000
- 25%
- Between £1,000,001 and £2,500,000
- 25%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Frank Rimerman
- ISO/IEC 27001 accreditation date
- Friday 26 July 2024
- What the ISO/IEC 27001 doesn’t cover
-
NA
Our ISO 27001:2022 certificate and SoA can be accessed in our trust center: https://security.revealdata.com/ - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Wednesday 10 September 2025
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- Our CSA Star Level 2 can be accessed in our Trust Center: https://security.revealdata.com/
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-