See how we secure regulated workloads
In this short overview, we walk through how Revion designs PCI-ready environments, what Revion takes off your plate, and how the shared responsibility model works in practice.

Who does what for PCI?
We use a simple shared-responsibility model so your security, compliance, and dev teams all know exactly who owns which PCI controls.
You own security in your application and the cardholder data it handles. Revion owns security of the hosting platform and the cardholder data environment (CDE). A short list of controls sits between the two and is run jointly.
| Responsibility | Owned by |
|---|---|
| Cardholder data (CHD) and how it is used | Customer |
| Application logic, workflows and user permissions | Customer |
| End-user devices, policies and training | Customer |
| Data retention and deletion policies | Customer |
| Third-party apps and integrations that access CHD | Customer |
| Access reviews | Shared |
| Audit logging | Shared |
| Vulnerability management | Shared |
| Incident coordination | Shared |
| CDE infrastructure: regions, zones and network segmentation | Revion |
| Networking, VPNs, firewalls and WAF | Revion |
| OS hardening, patching, backups and restores | Revion |
| Platform IAM for admin and support access | Revion |
| Security tooling, monitoring, alerts and response | Revion |