Logo
Riven

How we protect your apps and data

This page explains what Rivendoes to protect your applications and data, and what it doesn't do yet. Both matter before you run production workloads anywhere, so both are here.

Where your apps run

  • Applications run on AWS infrastructure in Mumbai (ap-south-1). Your data stays in India.
  • Each application runs in its own isolated container with its own resource limits, separated from other customers' workloads.

Data in transit

  • All traffic to Riven and to applications hosted on it uses HTTPS.
  • Custom domains get free SSL certificates that renew automatically.

Account access

  • You sign in with GitHub. We never see or store your GitHub password.
  • Workspaces support roles and permissions, so each team member gets only the access they need.
  • Audit logs record significant actions in a workspace: deploys, settings changes and membership changes.

Secrets and environment variables

  • Environment variables are encrypted at rest using AES. We never store raw values.
  • Secrets are decrypted only at runtime, for your own workloads.

Payments

  • Payments are processed by Razorpay. Card and UPI details never reach Riven's servers.

Monitoring

  • The platform is monitored continuously, and alerts come directly to the person who runs it.
  • Uptime history is public, including incidents.

Check our status page for the current state of the platform.

What we don't have yet

Most platforms leave this part out. We'd rather you knew now than found out during an incident.

No multi-server failover
Riven currently runs on a single-server setup. If that server has a problem, hosted applications can be down until it's resolved.
No formal certifications
We are not certified under SOC 2, ISO 27001 or any equivalent framework, and we don't hold audit reports of that kind.
Managed databases are not generally available
The managed database service is being rebuilt and isn't ready for production workloads yet.
No contractual uptime SLA
Standard plans don't come with a guaranteed uptime commitment. If you need one, talk to us before you commit to the platform.

This list changes as the platform does. It gets updated here, not quietly dropped.

Your data and your users' data

Data you give us to run your Riven account — your email, GitHub identity and billing information — is handled as described in our Privacy Policy.

Data inside your deployed applications belongs to you. Under India's Digital Personal Data Protection Act, you are the Data Fiduciary for it and we act as a Data Processor. We don't access your application data or databases except for support you've requested, to protect platform security, or where the law requires it. The full terms are in our Data Processing Agreement, which applies automatically. If you need a countersigned copy, email [email protected].

If something goes wrong

If we confirm a security incident affecting your data, we will notify affected customers by email without undue delay and within 72 hours of becoming aware, telling you what happened, what data was involved and what we're doing about it. Where the Digital Personal Data Protection Act requires it, we report the incident to the relevant authority. Updates stay on the status page until the issue is resolved.

Reporting a vulnerability

Found a security issue? Email [email protected] rather than posting it publicly, and you'll get an acknowledgement within 48 hours. We won't pursue legal action against anyone who reports a genuine issue in good faith, as long as they don't access, damage or exfiltrate other customers' data while doing it.

Last updated 13 September 2026