Two surfaces. Two postures.
Rivalta runs as two environments. This page is the public statement of how each handles your data, the operational hardening that sits underneath, and the governance posture that surrounds both.
Read the architectureDocuments stay on your desk.
PDFs, trust instruments, declarations pages, and tax returns are read in your browser. Only structured numeric and role-label fields enter Rivalta. Originals are never transmitted, never stored. A synthetic-identifier vocabulary maps to the real names locally; what leaves the browser is raw numbers, role labels, and pseudonyms.
// Browser-native parsing · zero document transmission
The same posture, on separate hardware.
When you try Rivalta through the complimentary Second Opinion or by opening a sealed handoff bundle, your documents are read in your browser — exactly as they are in the paid product. PDFs, declarations pages, and tax returns are parsed locally; only structured numeric and role-label fields, scrubbed of personally-identifying information, leave the device. The originals never transmit.
The evaluation environment runs on hardware separate from the paid product, with no network route between them, and the pseudonymized data it does receive is used to generate one report or analysis and deleted within 7–14 days — or immediately on conversion to a paid seat, whichever comes first.
// 7–14 day deletion window · separate infrastructure · cryptographically sealed reports
The plumbing, on the record.
TLS terminates at the server with modern ciphers; HSTS, frame-ancestors, and content-security-policy headers are enforced on every response. The paid product runs on Swiss-hosted bare metal under Swiss data protection law; the evaluation environment runs on European hosting under GDPR. Access to either environment is restricted to a small operator set with hardware-key authentication.
// TLS 1.3 · HSTS · CSP · hardware-key auth
When something goes wrong, we tell you.
Rivalta notifies affected account owners within seventy-two hours of confirming a security incident that affects their data. Notification arrives at the email address on the account and is mirrored on a public status page. It describes the nature and scope of the incident, the data categories involved, the remediation in progress, and a direct contact for follow-up.
Where law requires it, Rivalta notifies regulators separately on their own timelines — GDPR Article 33 for European data subjects, and the relevant state-level breach laws for United States residents.
Because of the browser-side anonymization, a breach of Rivalta’s servers does not produce a re-identifiable client roster. The professional’s machine remains the only place where the real names live; this is an architectural property of the platform, not a policy promise we can revise.
// 72-hour clock · GDPR Art. 33 · US state breach laws
The short list of third parties.
Rivalta engages a small set of subprocessors to operate the platform — hosting, payment processing, error monitoring, reasoning providers, and transactional email. The operational detail (what each one does, where it is hosted, what data category it receives) is on /privacy. Two security commitments sit on top of that list:
Attestation. Every subprocessor with access to engagement data is current on a third-party security attestation — SOC 2 Type II or an equivalent standard — reviewed by Rivalta on an annual cadence.
Advance notice. Account owners are notified by email at least thirty days before a new subprocessor with access to engagement data is added. Notice carries the subprocessor’s name, function, region, and attestation status, and the right to terminate the subscription if the change is unacceptable.
// SOC 2 Type II · 30-day notice · termination right
What we audit, and how often.
Rivalta is approaching its first public launch and does not yet hold a public third-party attestation. The schedule below is the cadence the product operates under from the first paid seat forward, and the first SOC 2 Type II examination begins within twelve months of public launch.
External. Annual SOC 2 Type II audit covering security, availability, and confidentiality controls. An independent penetration test runs annually against both the paid and evaluation environments, with remediation tracked to closure.
Internal. Quarterly review of access controls, dependency vulnerabilities, configuration drift, and the incident log. Findings that affect customer-facing risk are surfaced in the annual security update below.
Public update. On the anniversary of public launch, Rivalta publishes a summary of the audit cadence outcomes for the prior year — attestations refreshed, material findings remediated, and any change in subprocessor list. The update lives on this page.
// Annual SOC 2 Type II · annual pen test · quarterly internal
Built for the compliance conversation.
Data residency. Analysis runs on dedicated bare metal in Switzerland. Client data — including the pseudonymized substrate the engine operates on — never leaves the EU jurisdiction. The hosting layer is Hetzner AG, headquartered in Germany, operating Swiss-resident infrastructure.
PII architecture. Real client names and identifiers never reach Rivalta’s servers. The professional’s machine holds the names; a synthetic identifier vocabulary maps to them locally. The reasoning engine receives pseudonyms, role labels, and raw numbers — a substrate that is structurally insufficient to constitute a household-identifying record. This is an architectural property, not a configuration toggle. A breach of Rivalta’s infrastructure does not produce a re-identifiable client roster.
Audit trail. Every conflict the engine resolves is documented: what disagreed, why one path prevailed, what was rejected and on what grounds. The record is available to the professional and the firm. The undocumented conflict is the indefensible one; Rivalta records all of them. The Firm tier surfaces this record as a full audit packet alongside every Concord pass — conflicts surfaced, alternatives rejected, citations traced, dissent preserved.
Professional judgment gate. Rivalta surfaces analysis and documented reasoning; it does not execute. Every recommendation requires a credentialed professional to evaluate, approve, and act. Access is verification-gated — licensed professionals only. The engine is a tool for the professional’s judgment, not a replacement for it.
Patent-pending anonymization. The anonymization architecture is one of eleven patent-pending claims filed with the USPTO. Application 64/062,916, filed 2026-05-11, Polsinelli counsel. The capability is disclosed above; the mechanism is protected.
// Switzerland-resident · no client-identifying data on server · USPTO 64/062,916
An architectural property.
What you have read on this page is not a privacy policy in the usual sense. It is the description of an architecture. A breach of Rivalta’s servers does not produce a re-identifiable client roster because Rivalta’s servers were never designed to hold one. The professional’s machine remains the only place where the real names live, and that property travels with every customer, into every report, across every sealed handoff.
Competitors who built on shared CRM or portfolio-management data physically hold the household identifiers. They would have to rebuild from the foundation to reproduce what Rivalta has by design. The posture above is what is built; everything else on this page is the discipline that keeps it that way.
11 patent-pending claims · USPTO 64/062,916
Read the architecture