Security
SOC 2 Type II, the BAA,and who processes the data.
HIPAA compliant. One door for the current report and the vendor list.
The packet
What a review asks for
- Trust Center
Type II report and current vendor list
BAA
E-signed in the app before go-live
- security@rivvi.ai
Report or questionnaire
Guardrails
It does not diagnose, prescribe,or override clinical judgment
- Scope
- The agent stays inside the job you gave it. It does not give medical advice, and it hands off when a question needs a clinician.
- Crisis
- Distress and crisis signals escalate to a trained responder immediately, not at the end of a script.
- Access
- Who can see and do what is role-based, org-scoped, and auditable. Every action is logged.
- Record
- What happened, what was said, and what was escalated is written automatically. Nothing depends on memory.
Data
PHI stays insideHIPAA-eligible infrastructure
Protected health information never leaves that boundary and never trains third-party models. Your data is scoped to your organization. Every read and write is checked against that scope.
Type II report and current vendor listTCPA consent and opt-out run on every outreach path. Quiet hours follow your policy and the patient's locale. GDPR applies where we process personal data of people in the EEA.