Skip to content
rivvet

Security

Last updated September 26, 2026

rivvet connects to your inbox, calendar, calls and CRM. Here is how we protect that data and what we do and do not do with it.

Infrastructure

  • rivvet runs on established, managed cloud infrastructure.
  • All traffic to rivvet uses HTTPS (TLS), and stored data is encrypted at rest.
  • Secrets and encryption keys are kept in a managed vault, separate from application data.

Encryption of sensitive data

  • Email subjects and bodies synced from Gmail or Outlook are encrypted by rivvet with AES-256-GCM before they are stored, on top of disk encryption.
  • Access tokens for connected accounts are encrypted with AES-256-GCM.
  • Disconnecting an account revokes our access.

Access control

  • Every workspace is isolated. Each request is checked against the signed-in user’s workspace before any data is returned.
  • Admins set roles that control what each person can see and change, down to their own records, their team or the whole workspace.
  • Workspaces can require Google single sign-on.
  • Admin actions are recorded in an audit log.

Application security

  • Incoming webhooks are verified by signature.
  • Requests are rate-limited, and security headers are set on every response.
  • Permission checks are covered by an automated test suite that must pass before changes ship.

AI and your data

  • We never use your emails, calls, calendar data or records to train AI models.
  • AI features send only the content needed for the task, to providers whose terms do not allow training on it.
  • Prompt logs we keep for debugging are removed after 7 days.

Recording

  • Admins decide whether calls and meetings are recorded, and can set the announcement played at the start of dialer calls.
  • The notetaker joins meetings under a visible name so participants know it is there, and can be removed at any time.
  • Recordings are kept in rivvet’s own storage, not left with third parties.

Your control

  • Disconnect Google, Microsoft or any integration at any time.
  • Ask us to export or delete your data. See deleting your account.
  • The full list of providers that process data for us is in our Privacy Policy.

Reporting a vulnerability

If you believe you have found a security issue, email support@rivvet.io with the subject “Security report”. Please give us a reasonable time to fix it before sharing it publicly. We will not take legal action against good-faith research that avoids harm to our users and their data.