Security at riven
We take security seriously. Your data stays yours.
Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256).
No Training on Your Data
Your conversations and content are never used to train AI models.
Self-Host Option
Enterprise customers can deploy Riven on their own infrastructure.
SSO & SAML
Single sign-on integration with your identity provider.
Access Controls
Role-based permissions and audit logs for all actions.
Compliance
Working toward SOC 2 Type II certification. We answer security questionnaires honestly about where we are today.
Architecture and tenancy
Single-tenant by design
Riven is built as self-hosted, single-tenant AI for enterprises that demand control, compliance, and performance — your infrastructure or ours. Enterprise deployments run in a dedicated environment that is not shared with other customers.
Isolated cloud accounts
On the shared cloud service, every account’s conversations, files, API keys, and billing records are isolated per account with role-based access controls. No customer can read another customer’s data.
US-based infrastructure
The platform runs on Microsoft Azure in United States regions, fronted by Cloudflare for DDoS protection, TLS termination, and a web application firewall.
Self-hosted core services
Authentication, chat history, billing records, workflow automation, and internal messaging run on infrastructure we operate — not on third-party SaaS. Fewer external services means a smaller surface area for your data.
How your data is handled
What we store
Account details (name, email), conversations and files you save, usage records needed for billing, and payment status. Card numbers never touch our servers — payments are processed by Stripe.
Where prompts go
Models hosted on our own GPUs process your prompts entirely inside our infrastructure. When you choose a frontier cloud model (for example GPT, Claude, or Gemini), your prompt content is sent to that provider to generate the response — under API terms where providers do not train on API traffic.
Retention and deletion
Your conversations stay until you delete them. Deleting a conversation removes it from the product immediately and from backups on a rolling basis. You can request full account deletion at any time and we complete it within 30 days.
No training, no selling
We do not train models on your data, we do not sell your data, and we do not share it with advertisers. Usage analytics on our marketing site are aggregate and anonymous.
Subprocessors
The complete list of third parties that may process customer data, and exactly what each one does. Self-hosted enterprise deployments can eliminate every entry except payment processing.
| Provider | Purpose |
|---|---|
| Microsoft Azure | Cloud hosting and GPU compute (United States regions) |
| Cloudflare | DNS, CDN, TLS, DDoS protection, and web application firewall |
| Stripe | Payment processing — card data never touches Riven servers |
| Microsoft 365 | Transactional and support email delivery |
| Frontier model providers | OpenAI, Anthropic, Google, and similar — only when you select their models; prompt content only, no training on API traffic |
Responsible disclosure
Found a vulnerability? Report it through our contact form with details and steps to reproduce. We acknowledge reports within one business day, keep you updated while we fix, and credit researchers who report in good faith. We do not pursue legal action against good-faith research.
Security Questions?
Contact our security team for questionnaires, architecture reviews, or compliance documentation. We reply within one business day.
Contact Security Team