Security

Riley is the controlled gateway between AI tools and your business.

audit the outcome · verify activation · prove it every Friday

AI is only useful for real work if it can touch your real tools, and that should never mean handing out blank checks. Every surface that works through Riley gets scoped access, approval-gated writes, and a record of what happened. No vendor can honestly promise perfect security; what we promise is narrow access, a human gate on writes, and proof you can check.

How the gateway works

One door. Rules on the door. A record of who walked through.

  1. AI asks through Riley. Your dashboard, Slack, and any connected AI client (Claude, ChatGPT, Cursor, your own agents) all reach your business tools through the same door: Riley. No surface gets a side door.

  2. Riley enforces the rules. Scoped permissions, read / draft / write modes, and workspace isolation apply to every request. Anything that would change something outside your workspace stops in your approvals queue first.

  3. Every action leaves a record. Completed work lands in the outcome ledger as it happens, and finished jobs can carry a signed receipt you can verify. The record is written at action time, not reconstructed later.

Security principles

Every principle, labeled honestly.

Live means enforced in the product today. Partial means real but not complete, and the description says what is missing. Planned means a commitment, not a feature.

Least privilege

Live

Riley asks for the narrowest access that gets the job done. If a workflow only needs to read, that is all it gets.

Scoped permissions

Live

Each connection is scoped to what you grant during connect. Riley cannot reach past the scopes you approved.

Read, draft, and write modes

Live

Every integration works at one of three levels: read only, drafts for your approval, or writes that always pass through approval first.

Approval-gated writes

Live

Actions that change something outside your workspace wait in your approvals queue. You see what will happen before it happens.

Workspace isolation

Live

Your workspace's data, connections, and keys are scoped to your workspace. Requests are pinned to the signed-in workspace on every call.

Revocable access

Live

Disconnect an integration or revoke an access key at any time from Settings, and it stops working immediately.

Key rotation

Partial

You can mint a new key and revoke the old one whenever you want. Automatic scheduled rotation is not built yet, so rotation is a manual step today.

Secret redaction

Live

Connection credentials stay in the connection layer and sensitive fields are redacted from logs. Models work with results, not your raw secrets.

Audit trail

Live

Completed actions land in the outcome ledger as they happen, and security-relevant events are recorded separately. The record is written at action time, not reconstructed.

AI usage visibility

Partial

Work done through Riley is recorded wherever it came from. A per-surface usage breakdown is only partly built, so today you see the work but not yet a full per-surface report.

Memory controls

Live

What Riley remembers about your business is yours to read and edit from the dashboard, including brand voice and preferences.

Data export and deletion

Live

Export your workspace data or delete your account from Settings. Deletion uses a grace period, then your data is removed.

No hidden training on your data

Live

Your data is not used to train models behind your back. Any cross-customer learning is opt-in and off by default.

External AI cannot bypass approvals

Live

Requests arriving through connected AI clients pass through the same approval gate as everything else. No surface gets a side door.

Team roles

Partial

Role-based access for teams exists but is not yet fully surfaced across every page, so treat per-role boundaries as partial today.

AI access safety

Connect any AI. It still plays by your rules.

Keys are scoped, hashed, and shown once

AI access keys are minted per workspace in Settings and displayed exactly once. We store a hash, not the key, so nobody at Riley can read it back. Revoke any key at any time and it stops working immediately.

External AI cannot bypass approvals

A request from Claude, ChatGPT, Cursor, or any other connected client passes through the same approval gate as work you start in the dashboard. External writes wait in your queue no matter which surface asked.

Models never see your raw secrets

Connection credentials stay in the connection layer, and sensitive fields are redacted from logs. Models work with results, not your stored tokens or passwords.

See every surface Riley works from at Riley anywhere, or the technical details at developers.

Your controls

You hold the keys, the memory, and the off switch.

Approvals

Anything that writes outside your workspace waits for a named approval. You choose the posture: approve everything, or approve external writes only.

Memory controls

What Riley remembers about your business, including brand voice and preferences, is yours to read and edit from the dashboard.

Revoke integrations

Disconnect any integration or revoke any access key from Settings whenever you want. Access ends immediately.

Data export and deletion

Export your workspace data or delete your account from Settings. Deletion uses a grace period, then your data is removed.

Riley's playbooks and recommendations are updated as models, clients, and platforms change.

Compliance status

Honest, current, no fake claims.

Live today

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • OAuth-based connections (we never ask for your passwords)
  • Customer data never used for AI model training
  • Append-only security audit log of connection, approval, and account events
  • Per-workspace data isolation
  • Privacy and security controls for sensitive business workflows
  • Custom compliance requirements can be reviewed during setup
  • Automatic PII scanning on AI outputs

In progress

  • SOC 2 certification not claimed; readiness work in progress
  • Penetration test reports (annual, on request under NDA)

Data protection documents (DPA, subprocessor list) are available on request via support@hireriley.com or the contact form. Current posture always lives on /trust.

Security you can question, proof you can check.

Ask us anything about permissions, data handling, or access controls. And see what the record looks like on the proof side.