RivenGet started

Security at riven

We take security seriously. Your data stays yours.

Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256).

No Training on Your Data

Your conversations and content are never used to train AI models.

Self-Host Option

Enterprise customers can deploy Riven on their own infrastructure.

SSO & SAML

Single sign-on integration with your identity provider.

Access Controls

Role-based permissions and audit logs for all actions.

Compliance

Working toward SOC 2 Type II certification. We answer security questionnaires honestly about where we are today.

Architecture and tenancy

Single-tenant by design

Riven is built as self-hosted, single-tenant AI for enterprises that demand control, compliance, and performance — your infrastructure or ours. Enterprise deployments run in a dedicated environment that is not shared with other customers.

Isolated cloud accounts

On the shared cloud service, every account’s conversations, files, API keys, and billing records are isolated per account with role-based access controls. No customer can read another customer’s data.

US-based infrastructure

The platform runs on Microsoft Azure in United States regions, fronted by Cloudflare for DDoS protection, TLS termination, and a web application firewall.

Self-hosted core services

Authentication, chat history, billing records, workflow automation, and internal messaging run on infrastructure we operate — not on third-party SaaS. Fewer external services means a smaller surface area for your data.

How your data is handled

What we store

Account details (name, email), conversations and files you save, usage records needed for billing, and payment status. Card numbers never touch our servers — payments are processed by Stripe.

Where prompts go

Models hosted on our own GPUs process your prompts entirely inside our infrastructure. When you choose a frontier cloud model (for example GPT, Claude, or Gemini), your prompt content is sent to that provider to generate the response — under API terms where providers do not train on API traffic.

Retention and deletion

Your conversations stay until you delete them. Deleting a conversation removes it from the product immediately and from backups on a rolling basis. You can request full account deletion at any time and we complete it within 30 days.

No training, no selling

We do not train models on your data, we do not sell your data, and we do not share it with advertisers. Usage analytics on our marketing site are aggregate and anonymous.

Subprocessors

The complete list of third parties that may process customer data, and exactly what each one does. Self-hosted enterprise deployments can eliminate every entry except payment processing.

ProviderPurpose
Microsoft AzureCloud hosting and GPU compute (United States regions)
CloudflareDNS, CDN, TLS, DDoS protection, and web application firewall
StripePayment processing — card data never touches Riven servers
Microsoft 365Transactional and support email delivery
Frontier model providersOpenAI, Anthropic, Google, and similar — only when you select their models; prompt content only, no training on API traffic

Responsible disclosure

Found a vulnerability? Report it through our contact form with details and steps to reproduce. We acknowledge reports within one business day, keep you updated while we fix, and credit researchers who report in good faith. We do not pursue legal action against good-faith research.

Security Questions?

Contact our security team for questionnaires, architecture reviews, or compliance documentation. We reply within one business day.

Contact Security Team