How rivonOS protects your data.
What is in place today, written so your IT and procurement teams can check it. Features still being rolled out are listed separately and marked as not live.
Facts as of October 2026

Summary
Five things to know first. Everything here is live in production today.
- Each customer's data is kept separate in five layers, and automated tests check that separation on every release.
- People see only what their role and scope allow. Floor prices, costs, internal notes and bank details are hidden from roles without permission.
- Price activation, approval policies, invoice issue and agreement approval need a second person. The same person cannot be maker and checker.
- Every change is written to an audit log with who made it, when, from where, and what it looked like before and after.
- Customer data is hosted in AWS Mumbai (ap-south-1), encrypted at rest and in transit, with 7 days of point-in-time database recovery.
rivonOS does not hold SOC 2 or ISO 27001 certification today and does not offer an uptime SLA. We will say so here when that changes.
Tenant isolation
All customers share one rivonOS application. Five layers keep each customer's data apart:
- The customer (tenant) is taken only from the verified login session, never from anything the browser sends.
- Business code reaches the database through a scoped client that adds the tenant to every query. If the tenant is missing, the query fails instead of returning data.
- A code check stops business code from using an unscoped database client, so the first two layers cannot be skipped by mistake.
- Database keys include the tenant, so a record in one customer's data cannot point to a record in another's.
- Each customer's data lives in its own database schema, and the application connects to that schema only.
Automated isolation tests cover every kind of customer-owned record and run on every release. They try to read another customer's records and expect “not found”, so even the existence of a record is not revealed.
Access control
rivonOS comes with ten default roles, including a community manager role scoped to the centres a person runs. Each person's access is also limited by scope: their own records, their team, a centre, a city, a region, or the whole company.
Sensitive fields are hidden from roles that do not need them: floor prices, costs, internal notes and bank details.
Approvals and maker-checker
Four actions need a second person: activating a price, activating an approval policy, issuing an invoice and approving an agreement. The rule is enforced in the application and again by the database, which rejects a record where the checker is the same person as the maker.
Discount approvals follow your policy by level. Nobody can approve their own deal, and the same person cannot approve two levels of one request.
Audit log
Every change is written to the audit log in the same database transaction as the change itself, so a change cannot be saved without its log entry. Each entry records the person, the time, the IP address, the request and the record before and after.
The log is append-only: the application adds entries and does not change them. That rule is enforced by the application, not yet by the database itself.
Authentication
- Passwords are hashed with Argon2id and must be 12 to 128 characters long.
- An account locks for 15 minutes after 5 failed sign-in attempts, and requests are rate-limited.
- Access tokens last 15 minutes and are kept in memory, not in browser storage.
- Refresh tokens rotate on every use and are held in an HttpOnly, Secure, SameSite=strict cookie. If an old refresh token is reused, the session is ended.
- Sessions end after 7 days without activity, and after 30 days in any case.
Hosting and data residency
rivonOS runs in Amazon Web Services in Mumbai (region ap-south-1): application servers on EC2, the database on Amazon RDS for PostgreSQL 16, files on Amazon S3 and email on Amazon SES.
The database sits in private subnets with no public access. The application servers have no SSH access; administration goes through AWS Systems Manager.
Customer data is stored in India. The one exception is the AI assistant: if a customer chooses to turn it on, the records needed for a request are sent to OpenAI outside India. See AI and your data.
Encryption
- In transit: TLS 1.2 or 1.3 between browsers and rivonOS, with HSTS.
- At rest: encrypted database storage, encrypted server volumes, and files in S3 encrypted with a rivonOS key in AWS KMS.
- Sensitive fields, such as people's email addresses and phone numbers, notes and comments, are encrypted inside the application with a key for each customer, itself protected by AWS KMS.
- The application verifies the database's certificate on every connection.
- The file bucket is versioned and accepts only TLS connections.
- Application secrets are kept in AWS Systems Manager Parameter Store, not in code.
Backups
The database is backed up automatically, with point-in-time recovery for the last 7 days. Earlier versions of stored files are kept for 90 days.
rivonOS staff access
When a customer needs help, a rivonOS staff member can be given support access to that customer's workspace. That access is:
- read-only,
- limited in time,
- granted only with a stated reason,
- shown to the customer's users as a banner while it is active, and
- written to the customer's own audit log.
AI and your data
The AI assistant in rivonOS is off by default. It runs only for a customer that opts in.
If a customer opts in, the records relevant to a request, such as an account's history or an agreement's text, are sent to OpenAI to produce an answer. OpenAI processes them outside India. If you do not opt in, nothing is sent to OpenAI.
In rollout: not live yet
These are built or planned but are not running in production today. Do not count on them in a security review until this page says they are live.
- Planned, not live yet
Multi-factor authentication (MFA)
A second step at sign-in.
- Planned, not live yet
Single sign-on (SSO)
Sign in with your company identity provider.
Data protection
We build our practices against India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. For your company's data in rivonOS, your company decides what is collected and why, and rivonOS processes it on your behalf.
- Privacy questions and requests: privacy@rivonos.com
- Grievance officer: how to reach them
- How this website uses personal data: privacy notice
Report a vulnerability
If you think you have found a security problem in rivonOS or this website, email security@rivonos.com with the steps to reproduce it. Please do not access or change other people's data, and give us reasonable time to fix the problem before you share it. We will confirm we have received your report.
Subprocessors
| Company | What for | Where | When |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage and email (Amazon SES) | Mumbai, India (ap-south-1) | Always |
| OpenAI | AI assistant answers | Outside India | Only if your company turns the AI assistant on |
Bring your security questionnaire.
We will answer it in writing, and walk your IT team through how isolation, access and approvals work in the product.
