1. Zero Data Retention (ZDR) Guarantee
At Rivenstack AI, data privacy is paramount. All patient records, faxes, audio call streams (Veronica AI), and financial invoices (FinBot-AI) processed through our agent pipelines are executed purely within isolated, ephemeral memory containers.
Zero Retention Commitment: Customer data is never cached, logged permanently, or used for public AI foundation model training under any circumstances.
2. Data Encryption & Onshore Sovereignty
All data in transit is protected using TLS 1.3 encryption with strict Perfect Forward Secrecy (PFS). Data at rest is encrypted using AES-256 cryptographic standards.
- Onshore cloud deployment options (AWS / Azure local region clusters)
- Customer-managed encryption keys (CMEK) available for VPC enterprise tiers
- Strict network isolation with VPC peering and IP whitelisting
3. Regulatory Compliance (HIPAA, GDPR & ISO27001)
Rivenstack AI systems are engineered to meet global enterprise compliance frameworks:
- HIPAA Compliance: Comprehensive Business Associate Agreements (BAAs) provided for clinical deployments.
- SOC2 Type II: Independently audited controls across security, availability, and confidentiality.
- GDPR & ISO27001: End-to-end data subject access rights and automated compliance logging.
4. Enterprise Terms of Service & SLA
Rivenstack AI guarantees a 99.99% operational uptime Service Level Agreement (SLA) for enterprise deployments, backed by 24/7 dedicated engineering support and 1-hour critical issue response windows.