Skip to content

Security architecture

Security is the first question a serious enterprise asks, and it deserves a clear answer. This page describes how Rival protects your data and access at the platform level. [VERIFY: this page should be reviewed and confirmed by Rival’s security team before publishing — the specifics below are a framework, not confirmed claims.]

Your data is protected both in transit (as it moves between systems) and at rest (as it’s stored), using strong encryption — the standard practice of scrambling data so it’s unreadable without the key. [VERIFY: confirm encryption standards in transit and at rest.]

Access starts with strong authentication: verifying that people are who they say they are before they can do anything. In the enterprise, this connects to your own identity provider through SSO, so access is governed by your existing security systems rather than a separate island of logins.

On top of the platform’s protections sit the controls you configure: roles and permissions, org-wide guardrails, approvals, and audit logs. Security architecture and governance work together — one protects the environment, the other controls what happens inside it. See Governance & Approvals.

Platform security and your configuration both matter. Rival secures the platform; you secure your usage of it — approving the right connectors, granting least-privilege access, and reviewing your audit trail. Strong security is the two working together.

A security team evaluating Rival maps their checklist against this architecture: encryption in transit and at rest, SSO tied to their identity provider, least-privilege roles, and audit logs for accountability. Each maps to a control described here — turning “is it secure?” into a concrete, checkable conversation.