RivenGet started

Search docs

Find a page across the Riven documentation

Riven Trust

Live

The trust centre: security posture, data handling, subprocessors, and compliance commitments, published rather than provided on request.

Service
surfaces_trust

Trust is where the platform states, in public and in current form, how it handles data. It exists so that a security review can start with reading rather than with a questionnaire.

What it covers#

  • Data handling — what is stored, for how long, and who inside Riven can reach it.
  • Residency — where data lives, and the sovereign and on-premise deployment options that keep it in your estate.
  • Subprocessors — the third parties involved in delivering the platform, including which cloud model providers may see a prompt when a request falls back.
  • Security controls — encryption in transit and at rest, secret handling via Keymaster, and access review.
  • Compliance — current certifications and the status of those in progress.

Sovereign deployment#

For workloads that cannot use third-party model providers at all, Riven runs entirely on its on-prem fleet with cloud upstreams disabled. Ancillary capabilities follow the same rule: avatar and likeness generation, for example, uses HeyGem in sovereign deployments so media never leaves the estate.

Key protection#

Riven stores only a cryptographic hash of an API key — the full value is displayed once, at mint time. Rotation and revocation are instant and preserve plan standing. See Authentication & keys.

Questions the trust centre does not answer belong at rivenai.io/contact. Do not send credentials or customer data in a support message.