Riven Trust
LiveThe trust centre: security posture, data handling, subprocessors, and compliance commitments, published rather than provided on request.
- Service
- surfaces_trust
Trust is where the platform states, in public and in current form, how it handles data. It exists so that a security review can start with reading rather than with a questionnaire.
What it covers#
- Data handling — what is stored, for how long, and who inside Riven can reach it.
- Residency — where data lives, and the sovereign and on-premise deployment options that keep it in your estate.
- Subprocessors — the third parties involved in delivering the platform, including which cloud model providers may see a prompt when a request falls back.
- Security controls — encryption in transit and at rest, secret handling via Keymaster, and access review.
- Compliance — current certifications and the status of those in progress.
Sovereign deployment#
For workloads that cannot use third-party model providers at all, Riven runs entirely on its on-prem fleet with cloud upstreams disabled. Ancillary capabilities follow the same rule: avatar and likeness generation, for example, uses HeyGem in sovereign deployments so media never leaves the estate.
Key protection#
Riven stores only a cryptographic hash of an API key — the full value is displayed once, at mint time. Rotation and revocation are instant and preserve plan standing. See Authentication & keys.
Questions the trust centre does not answer belong at rivenai.io/contact. Do not send credentials or customer data in a support message.