Trust
Security at Rivetmoss
Last updated 27 September 2026
You store certificates, inspection records and training evidence with us. This page explains, in plain terms, how that information is kept private to your company and who can see it.
Your data is separate from every other customer's
Every record belongs to one company. Each request is checked against the signed-in person's membership before any data is read or changed, so staff at one company cannot see another company's facilities, obligations or documents.
The database's public data API is switched off: every table has row-level security with a policy that denies it all access. Your records are read and written only through the Rivetmoss application, which checks your company membership on every request.
Encryption and hosting
- All traffic uses HTTPS (TLS). Browsers are told to refuse unencrypted connections to Rivetmoss.
- Data is stored in the United States with Supabase (on AWS, us-east-1), encrypted at rest with AES-256. The application runs on Vercel. Both providers hold SOC 2 Type 2 attestations.
- Evidence files are private. They are handed out only to signed-in members of your company, through links that expire after a minute and download the file rather than opening it as a web page.
Who in your company can do what
Each person has one role: administrator, facility coordinator, reviewer or read-only auditor. Roles are enforced on the server for every action, not just hidden in the screen. Only administrators can invite people or change roles.
A record of who touched your evidence
Uploading, opening and deleting a document are recorded in that obligation's history with the person's name and the time, so when an auditor asks who handled a record, the answer is already there.
Accounts and sign-in
- New passwords must be at least 12 characters. Passwords are stored only as hashes.
- Repeated sign-in attempts are rate-limited to slow down password guessing.
- Sessions expire after a week of inactivity.
Uploads are checked before they are stored
Only documents, images and spreadsheets can be uploaded, and each file's signature is checked against the type it claims to be. A web page or program renamed to look like a PDF or an image is refused.
AI document review
When you upload evidence, Rivetmoss sends that document to Anthropic's Claude API to judge whether it proves the requirement. Under Anthropic's commercial terms, data sent through the API is not used to train their models by default. The verdict is advice: a named person at your company stays responsible for the compliance decision.
Reporting a security issue
If you believe you have found a vulnerability, email hello@rivetmoss.contact with the details. We will acknowledge your report and keep you informed while we fix it. Please do not access other customers' data or disrupt the service while testing.