Skip to content

Trust Centre

You’re in safe hands.

Everything about engaging with RIVER. Your questions answered, your data protected, and a team who has your back.

100% NZ built. Māori and Pacific owned. Enterprise proven, sovereign deployments.

Common questions

Straight answers to what we get asked most.

Have a different question? Contact us or

Our commitments

The same terms for everyone, in every engagement.

Clear terms, transparent pricing, and a clean exit if you ever need one. None of it is negotiated deal by deal.

  • You own your data, your workflows and your IP. Always. We keep only the Catalyst platform, which is what lets us ship improvements across every client.
  • We never train public models on your data. And we configure every third-party AI provider to prevent training on it too.
  • Sovereign hosting, or your own cloud. Three deployment models, from RIVER-managed in New Zealand or Australia to fully customer-managed.
  • Clear terms, and a clean exit. Published terms, capped liability, and a full export of your data in standard formats if you ever leave.
How we handle AI data

Your data, handled plainly.

A plain-language summary of how we handle data across AI engagements.

Your data stays yours

You own your data, your workflows and your IP. Always.

No training on your data

We don’t use client data to train public AI models, and we configure third-party providers to prevent it.

Choose your deployment

RIVER Cloud, your own cloud, or fully customer-managed. Your call, and the platform migrates between them.

Enterprise access controls

Role-based access, SSO and multi-factor sign-in, and exportable audit logs as standard.

A clean exit, always

A full export of your data in standard formats on termination, then deletion once you confirm.

NZ and AU compliance

Built for the New Zealand Privacy Act 2020 and the Australian Privacy Principles.

Security & compliance

Built to the frameworks enterprise security expects.

Our controls, AI governance and operational practices are built to these standards. Independent certification is in progress.

Information Security

ISO 27001

  • Formal risk assessment on every engagement
  • MFA, role-based access and least-privilege across all systems
  • Encryption in transit and at rest, with documented incident response

Aligned - certification in progress

AI Governance

ISO 42001

  • Human oversight on AI outputs, especially high-stakes decisions
  • Model selection on requirements, not vendor lock-in
  • Data-quality governance and no-training provider configurations

Aligned - certification in progress

Trust Services

SOC 2 Type II

  • Security, availability, confidentiality and privacy criteria
  • Controls tested over a sustained period, not a point in time
  • Independent verification once the audit begins

Aligned, audit planned