Security model
Rivora is designed around separated business workspaces, authenticated access and role-based permissions. Security is a shared responsibility: Rivora protects the platform, while organization owners control who they invite and what data they enter.
Access controls
- Authentication through configured identity providers such as Google and Microsoft.
- Organization and business memberships determine which records a user can access.
- Role-based permissions distinguish platform administration from business-level access.
- Database Row Level Security is used to restrict access to protected records.
Infrastructure and secrets
Rivora uses managed cloud infrastructure. Public browser credentials are separated from privileged server credentials. Privileged service keys, where used, should be stored only in protected server-side environment variables and must not be committed to public source code.
Incident response
Rivora maintains an incident-response process designed to identify, contain, investigate and remediate security events. Where applicable law requires notification of affected customers or individuals, Rivora will provide notice within the legally required timeframe based on the facts of the incident.
Customer responsibilities
Customers should use trusted email accounts, protect provider credentials, promptly remove former staff, assign only the minimum access needed, avoid entering prohibited sensitive data, and contact Rivora if they suspect unauthorized access.
Security contact
Report suspected security issues to andrew@rivasit.net. Please do not include passwords, full financial account credentials, medical records or other highly sensitive content in the initial message.