RIVT Security
Effective July 9, 2026. RIVT is built for contractors, subcontractors, and skilled tradespeople. Security and privacy matter because the product handles work records, messages, photos, account data, and subscription status.
- RIVT uses HTTPS for production traffic.
- Passwords are hashed before storage and are not stored in plain text.
- Account sessions use protected server-issued cookies.
- Private API routes require a real authenticated account.
- Jobsite addresses are not public and are shared only under product rules for real work relationships.
- Uploads are stored in managed cloud object storage when users upload photos or attachments.
- Subscription billing is handled through Stripe. RIVT does not store full card numbers.
- Production monitoring checks health, storage dependencies, and private-route protections.
Payments
RIVT uses Stripe-hosted billing flows for subscriptions. Payment card details are handled by Stripe's payment infrastructure, not stored directly by RIVT.
Responsible disclosure
If you believe you found a security issue, email support@rivt.pro with the subject line "Security report." Please include the affected page or endpoint, steps to reproduce, and any screenshots or request IDs that help us verify the issue.
Do not access another user's account, download private data, disrupt service, or publicly disclose a vulnerability before RIVT has had a reasonable chance to investigate and fix it.
What we do not claim yet
RIVT is in beta. We do not currently claim SOC 2 certification, PCI certification by RIVT, government accreditation, background-check verification, or a completed third-party penetration test. When those reviews are completed, this page will be updated with the real evidence.
Contact
General support: support@rivt.pro. Security reports: support@rivt.pro with the subject "Security report."