Security

SECURITY

How Riverton approaches security

Riverton is a shared workspace for business and client information, so security is treated as a foundational requirement rather than an afterthought. This page explains our approach and what to verify before adopting the platform.

OVERVIEW

Security in a shared client workspace

A client portal brings business and client information into one place, including messages, files, documents, tasks, and approvals. Because that information moves between a business and its clients, security is central to whether a workspace can be trusted with real client work.

This page is intended to separate two kinds of information: Riverton-specific practices that can be verified, and general security considerations that any business should think about when adopting client-facing software. Where a specific detail has not yet been documented or verified, that is stated directly rather than implied.

Statements on this page are limited to what has been verified. Where a control, certification, or technical detail has not been confirmed, this page says so rather than assuming an industry-standard answer applies to Riverton.

CLIENT WORK

What security means for client work

Security questions around a client workspace are different from general IT security questions. They center on the information that moves between a business and its clients inside the workspace.

Client information

Details clients share with a business as part of ongoing work.

Documents and files

Files and documents exchanged between a business and its clients.

Access

Who can reach a workspace, and what they are able to see once inside it.

Riverton’s approach to security is built around this Business + Client → Shared Workspace model, rather than around generic enterprise IT concerns unrelated to client work.

PRACTICES

Riverton security practices

The categories below represent the areas of security relevant to a client workspace. Riverton’s specific practices in each category are being documented and verified prior to publication.

  • Data protection — needs verification before publication
  • Account security and authentication — needs verification before publication
  • Access controls and permissions — needs verification before publication
  • Infrastructure and hosting — needs verification before publication
  • Encryption in transit and at rest — needs verification before publication
  • Data storage and backups — needs verification before publication
  • Monitoring and incident response — needs verification before publication
  • Vendor and subprocessor management — needs verification before publication

These categories will be updated with specific, documented information as each control is confirmed. Riverton does not publish assumed or industry-typical claims in place of verified detail.

DATA

Data and client information

Riverton workspaces are used to store and exchange business and client information, including uploaded files, documents, and account details. How this information is retained, deleted, and owned is governed by Riverton’s policies.

Specific details on data retention, deletion, and ownership are being confirmed against current product behavior and policy documentation before being stated here.

Applies to

  • Business data
  • Client data
  • Uploaded files and documents
  • Account information
ACCESS

Access and account security

Controlling who can reach a workspace, and what they can see once inside it, is central to client portal security. Riverton’s specific authentication and access-control functionality is being verified before being described here.

Authentication and login

Login security details, including password requirements and any additional authentication options, require verification before publication.

Roles and permissions

The granularity of business and client access — by workspace, project, or document — requires verification before publication.

INFRASTRUCTURE

Infrastructure and technical security

Technical safeguards — including hosting environment, encryption in transit and at rest, network security, backups, and security testing — are important evaluation criteria for any client workspace. Riverton’s specific technical details in this area are being documented and verified before publication.

Riverton does not use unverifiable language such as “bank-level security,” “military-grade encryption,” or “100% secure.” Claims on this page are limited to what can be substantiated.

PRIVACY & COMPLIANCE

Privacy and compliance

Riverton’s privacy and compliance posture is governed by its published policies. Formal certifications — such as SOC 2, ISO 27001, GDPR, or HIPAA — are only referenced on this page where current documentary evidence confirms that status.

At this stage, no compliance certification is being claimed on this page. This section will be updated if and when a specific certification is verified and documented.

SHARED RESPONSIBILITY

Customer responsibilities

Security in a shared workspace is a shared responsibility. Alongside Riverton’s own practices, businesses using the platform can help protect their client work by:

  • Using strong, unique account credentials
  • Reviewing who has access to each workspace
  • Removing access when it is no longer needed
  • Handling sensitive client files with appropriate care
  • Following internal security policies for client-facing work
WHY IT MATTERS

Security supports clearer client work

A structured client workspace can help a business keep client communication, files, and approvals organized in one place. That organization does not by itself guarantee security — it depends on the practices behind the workspace. Riverton’s goal is to make both the organization and the underlying practices something customers can evaluate clearly.

DOCUMENTATION

Security and privacy documentation

The following documents govern how Riverton handles information. Links will be added here once each document is published and confirmed.

  • Privacy Policy — /privacy-policy/
  • Terms of Service — /terms-of-service/
  • Data Processing Agreement — [URL TO BE CONFIRMED]
  • Subprocessor information — [URL TO BE CONFIRMED]
FAQ

Security questions

Is Riverton secure?

Riverton is built around a shared workspace for business and client information, and security is treated as a foundational requirement. Specific technical and procedural details are being verified and will be published here as they are confirmed.

How does Riverton protect client information?

Client information is handled according to Riverton’s data protection practices. Specific controls are being documented and verified before being described in detail on this page.

How does Riverton protect business data?

Business data is treated with the same data protection approach as client information. Specific details require verification before publication.

Is client data encrypted in Riverton?

Encryption details require verification against current product and infrastructure documentation before they can be confirmed here.

Does Riverton use access controls?

Access and permission functionality require verification against the current product before specific details can be published.

Does Riverton support two-factor authentication or MFA?

This has not yet been confirmed. This answer will be updated once verified.

Where is Riverton data stored?

Hosting and data-storage details require verification before they can be published on this page.

Is Riverton GDPR compliant?

No GDPR compliance status is being claimed at this time. This section will be updated if formal documentation confirms a specific status.

Does Riverton have SOC 2 or ISO 27001 certification?

No SOC 2 or ISO 27001 certification is being claimed at this time. This section will be updated if a certification is obtained and documented.

How can I contact Riverton about security questions?

Questions about Riverton’s security practices can be directed through our contact page.

GET STARTED

Questions about how Riverton handles security?

Reach out directly, or explore how Riverton brings client communication, files, and approvals into one shared workspace.