Security architecture
Security is the first question a serious enterprise asks, and it deserves a clear answer. This page describes how Rival protects your data and access at the platform level. [VERIFY: this page should be reviewed and confirmed by Rival’s security team before publishing — the specifics below are a framework, not confirmed claims.]
Data protection
Section titled “Data protection”Your data is protected both in transit (as it moves between systems) and at rest (as it’s stored), using strong encryption — the standard practice of scrambling data so it’s unreadable without the key. [VERIFY: confirm encryption standards in transit and at rest.]
Authentication
Section titled “Authentication”Access starts with strong authentication: verifying that people are who they say they are before they can do anything. In the enterprise, this connects to your own identity provider through SSO, so access is governed by your existing security systems rather than a separate island of logins.
Enterprise controls
Section titled “Enterprise controls”On top of the platform’s protections sit the controls you configure: roles and permissions, org-wide guardrails, approvals, and audit logs. Security architecture and governance work together — one protects the environment, the other controls what happens inside it. See Governance & Approvals.
The shared-responsibility idea
Section titled “The shared-responsibility idea”Platform security and your configuration both matter. Rival secures the platform; you secure your usage of it — approving the right connectors, granting least-privilege access, and reviewing your audit trail. Strong security is the two working together.
A quick example
Section titled “A quick example”A security team evaluating Rival maps their checklist against this architecture: encryption in transit and at rest, SSO tied to their identity provider, least-privilege roles, and audit logs for accountability. Each maps to a control described here — turning “is it secure?” into a concrete, checkable conversation.