Privacy & security
Your conversations and tasks belong to your account and workspace. The full, current statement of Riven’s security and data-handling commitments lives at the Riven Trust Center.
- Your data, your workspace. Conversations, uploads, and task history are scoped to your account; workspace-level retention and visibility are managed by your workspace admin.
- API keys are protected at rest. Riven stores only a cryptographic hash of your API keys — the full key is shown once at mint time. Rotate or revoke any key instantly (see Authentication & keys and Riven Keymaster).
- Transport security. All Riven surfaces and API endpoints are served over HTTPS, terminated by Riven Edge Proxy.
- Sovereign inference. Requests are served on Riven-operated hardware first — see the on-prem fleet and cloud fallback for when a third party is involved.
Questions the Trust Center doesn’t answer? Reach us via rivenai.io/contact. The reporting surface is Riven Trust.