Rivet is designed around organization scope, relationship membership, bounded guest access, and private-by-default system links.
Every read is gated by scope: your organization, the relationships you are a member of, and the specific conversations you are invited to. Accumulating one grant never widens another.
Your team, settings, systems, and internal channels belong to your organization. Cross-organization reads return only an approved public profile.
Shared documents, conversations, and workflow are visible only to members of that relationship — on both sides, at the scope each side controls.
An outside participant sees only the conversation they were invited to — never the workspace, relationship, or documents around it.
Security documentation is available to evaluating teams under NDA. Questions about our posture, data handling, or financial-partner compliance: contact security.
Members can protect a Rivet account with a passkey, an authenticator app, a text message, or an emailed code, and get ten single-use recovery codes when they set the first one up. The requirement applies everywhere an account can be opened — password sign-in, single sign-on, and password reset — so there is no side door around it.
Two things worth stating plainly. A second factor is a choice an administrator makes — it is off until an organization turns it on. And passkeys are the only one of the four that resists phishing: a convincing replica site can harvest and replay a code from an app or a text in real time, so an organization requiring any second factor has raised a floor rather than closed that gap.
We welcome reports from anyone who finds a security problem in Rivet, in good faith.
Machine-readable pointer: /.well-known/security.txt (RFC 9116). Rivet is a hosted service; there are no customer-installed versions.