Trust by design
Riv is built so the sensitive parts stay safe: deterministic decisions, human approval where it matters, and an immutable ledger.
Human in command when it matters
The engine handles routine on its own. When a policy says hold, the spend becomes pending: a human approves (counts toward the agent's limit) or rejects (denies) — in the Approvals tab, with authorship recorded.
- ✓ Deterministic decision: allow, block or require approval.
- ✓ Human approval with authorship recorded in the ledger.
- ✓ Phase 1 with no custody: only the credential hash.
snowflake · exceeds monthly cap
A ledger that never gets erased
Every decision — allowed, blocked or pending — lands in the ledger and stays. Soft-delete everywhere: history is immutable by design, ready for audit at any time.
What actually protects your account
If a policy can't be evaluated or the engine errors, the spend is denied. There is no silent allow path.
Tenant isolation is enforced by the database itself, not only by application code.
Owner, admin and member roles gate what each person can change — in the app and in the admin panel.
Public endpoints and sensitive actions are rate-limited per IP across all instances.
The administrative panel runs on isolated auth with mandatory two-factor authentication.
Phase 1 — pure software, no custody
Riv does not custody or move real money in Phase 1. We only store the credential hash. Real custody and settlement arrive in Phase 2, via a licensed partner.