RIVER FAQ
Common enterprise purchasing questions, answered clearly.
RIVER FAQ
RIVER Group Limited · New Zealand · 5 September 2026
The questions buyers and procurement teams ask most, with clear answers on data, ownership, deployment, security and exit.
Getting started
What exactly are we buying?
A dedicated, single-tenant instance of RIVER's managed AI platform, operated by RIVER. You receive:
- A dedicated version of the RIVER platform for your organisation
- The agreed implementation services described in the Proposal
- Ongoing platform operations, support, and governance
This is not a shared SaaS product. Your instance is yours alone, built around your data, your workflows, and your team.
See Terms - Clause 1, and the Terms in full.
How soon will we see something real?
Weeks, and every phase ships something. The Readiness Check tells you where you stand in minutes. Your first capability, working with your real data, is live within weeks as the first module of your command centre.
There is no strategy-only phase where nothing gets built, and no year of consulting before anything runs. You get an early, real win you can take to your board.
What do we need in place before a platform build?
A named executive sponsor, budget capacity, and a real appetite to change how the team works. Change management runs from day one, so someone on your side has to own it with us.
Anyone can start, though. If you are not there yet, coaching or the Readiness Check is the honest first step, and we will say so.
The retainer and pricing
How is pricing structured?
There are three ways to buy, and they combine:
- The Retainer: a monthly fee from $5,000, moving up or down a tier in any month. This is how most clients work with us.
- A Sprint: a fixed-scope piece of work from $5,000, priced and agreed before it starts.
- A Build: the largest kind of sprint, sized against the scope of the platform. Treat the published figures as a budget to plan against rather than a fixed price.
Every figure is published on the site, and the tiers are on the Retainer page. There is no separate setup fee, no per-seat charge, and no minimum term.
Price ranges reflect the diversity of engagements we deliver, from focused AI pilots to organisation-wide platforms. Your Proposal will specify exact pricing based on your scope, modules, and deployment model.
See Terms - Clause 3.
Do we get a set number of hours?
We do not sell hours. A quiet month should not cost you unused time, and a busy one should not run out halfway through the work.
The tier sets the pace. To budget against, the $5,000 Retainer is typically 15 to 30 hours of change a month, with hosting and support alongside it. Retainer Black delivers around three times the output, because at that level more of the month goes into delivery and less into planning.
A senior architect scoping an integration and a developer building it are not the same hour, so we price the outcome and the cadence rather than a timesheet. There is no per-seat charge and no new quote each time you add a person or a report.
What is included in the ongoing monthly cost?
Defined in the Proposal. Typically includes:
- Platform operations (monitoring, backups, updates)
- Security and access control management
- Support and refinement cycles for the agreed scope
- Governance and adoption support
- Regular value check-ins and roadmap guidance
- Access to the RIVER platform, and remediation of Material Defects - reproducible failures preventing core functions - in RIVER-delivered components
Pricing uses value-based bands, not per-seat pricing, so the model supports broad adoption without individual subscriptions. More people using it is a good thing.
What sits outside it, and is handled as a change request or a separate agreement:
- New features or scope changes
- AI output refinement (prompt tuning, model selection)
- Issues caused by Client Systems or data
- Platform Support (dependency updates, security patches, framework upgrades), unless your Proposal includes it
See Terms - Clause 2, Clause 3.
What is Platform Support, and is it included?
Platform Support is the ongoing technical upkeep required to keep the platform and its dependencies current: software dependency updates, package and framework upgrades, API compatibility changes, security patches, and environment configuration updates.
Platform Support is not included by default unless your Proposal says so. It is typically delivered as part of a retainer or managed services engagement.
Why this matters: software platforms depend on third-party packages, APIs and frameworks that evolve over time. Without ongoing upkeep, dependencies can become outdated or incompatible. That is not a defect in RIVER's code. It is what happens to any software left unmaintained.
If this upkeep is required and the Client has not engaged RIVER for ongoing Platform Support, RIVER will notify the Client, provide a scope and estimate, and agree the work in writing before proceeding. We recommend all Production engagements include Platform Support.
See Terms - Module B, Module C.
How does "we deliver or we work for free" work?
If a month passes and we cannot point to something we delivered against your roadmap, you do not pay for it. Where hosting is bundled into your monthly, hosting still runs, so the difference is free.
The risk sits with us, not you. A delivery means something real you can point to at your review: a capability running that was not before, a workflow live, an integration in place, a job that was manual now automated. Not a status update, and not a meeting. It assumes the few things only you can give us: agreed access, your data, and one person on your side who can make a call.
Will the AI usage cost blow out?
AI usage is included in your platform fee, up to an agreed allowance, with no separate bill and no credits to top up. If usage runs beyond that allowance, the extra is charged at cost, set out in your Proposal, so there is no surprise on the invoice.
How does contracting work for a pilot versus production?
Two standard modes, confirmed in the Proposal:
- Pilot: fixed setup plus a minimum of one month. Designed for proof of value with a clean exit, and no early termination fees. Typically up to 6 months.
- Production: minimum term typically twelve months, supporting stable operations, governance and ongoing optimisation. Continues month to month after the minimum term.
This keeps pilots lightweight while making sure production deployments stay reliable and supportable.
See Terms - Module C.
What are the payment terms?
- Invoices are payable within 14 days of invoice date
- Late payment attracts interest at 1.5% per month on overdue amounts
- The Client is liable for reasonable collection costs on overdue amounts
- If any invoice remains unpaid 30 or more days past due, RIVER may suspend platform access on 5 business days' written notice
See Terms - Clause 3.
What third-party costs sit outside your fees?
The services you already buy. Your cloud subscription, Microsoft subscriptions, and any system we connect to are billed directly by those providers. For private deployments, infrastructure consumption is billed through your own cloud subscription.
Delivery and adoption
What does working with RIVER look like?
We use an iterative delivery approach: brief, build, review. A member of our senior team champions every project.
- Align: we work with your leadership team to identify the highest-value opportunities and agree the best path forward.
- Ship: working software delivered in regular milestones. Real users, real data, real feedback from the start.
- Scale: expand what works across the organisation, in quarterly milestones.
Your team is embedded in the process from day one. We deliver working software, not status reports.
See Terms - Clause 2.
What are our client responsibilities?
Client responsibilities are kept simple so delivery stays fast:
- Nominate a pilot cohort and decision-makers
- Provide access to relevant knowledge sources and approved materials
- Support SSO and access setup, where required
- Provide timely feedback and approvals on a regular cadence
- Confirm operational boundaries (what the AI can and cannot do)
We recommend a regular decision cadence to maintain momentum. Where client delays exceed 20 business days, re-mobilisation costs may apply.
See Terms - Clause 2.
Will our team actually use it?
Only if they never have to log into another system. That is the whole adoption problem, and we design it out rather than explaining it away.
We reduce adoption risk through:
- Clear use-case boundaries and a shared picture of what good looks like
- Guided onboarding for the pilot cohort
- Templates and workflow design aligned to how you already operate
- Iterative refinement cycles as real usage comes in
- Champion networks built into delivery
Change management is not an add-on. It is built into how we deliver.
See Terms - Clause 2.
How do we measure value?
Value tracking is built into delivery:
- Success metrics agreed during scoping (cycle time, consistency, reduction in rework)
- Baseline captured early
- Usage and workflow outcomes monitored
- Measurable improvements targeted within the initial deployment or pilot period
We measure what matters in your domain, not generic "hours saved".
See Terms - Clause 2.
What SLA and support levels apply?
We typically target 99.5% availability for the managed environment, excluding outages of third-party providers, client-driven impacts, and scheduled maintenance windows.
Support levels and response targets are defined in the Proposal:
- Pilots: business-hours support with reasonable response targets
- Production: can include defined uptime targets, on-call escalation, and where agreed, service credits
Planned maintenance is notified at least 3 business days in advance and scheduled outside business hours where practical. Emergency or security-related maintenance may use shorter notice.
AI services are probabilistic. We design, ground, test and monitor AI features with reasonable care, but AI output varies by nature and we cannot guarantee 100% accuracy. Human-in-the-loop oversight is what protects against that.
See Terms - Module C, Module D, Clause 5.
Can we extend or scale later?
Yes. Scaling follows proven success, not sunk cost. Expansion typically includes additional workflows and operational agents, broader knowledge domains, rollout to more teams or business units, automation enablement where it is needed and governed, additional environments, and migration between deployment models.
Each new module builds on the existing platform, so expansion gets faster rather than harder.
See Terms - Clause 2.
Your data and AI
Does RIVER use our data to train AI?
No. Customer Data is not used to train public AI models.
Where third-party AI services are used, we use configurations designed to prevent provider training on Customer Data. If you require additional restrictions, such as client-held keys, private model routing or provider limitations, these are handled as part of the agreed deployment approach.
See Terms - Clause 4.
What if the AI gets it wrong?
It answers from sources you approve, shows where each answer came from, and says it does not know rather than guessing. We curate what it reads rather than pointing it at everything, because searching everything at once returns confident, conflicting answers, which is worse than no answer.
Anything consequential keeps a person in the loop, earning more autonomy as the evidence comes in. Our standard terms (clause 5) set out how AI is used and where responsibility sits.
Where is data hosted and processed?
The deployment options, selected in the Proposal:
- RIVER Cloud (Managed): hosted and operated by RIVER in New Zealand or Australia, as agreed. Standard security controls, monitoring, backups and upgrades. The default option, included in the monthly fee.
- RIVER Sovereign: data-residency hosting in New Zealand or Australia via SiteHost (ISO 27001 certified), as set out in your Proposal. Your data stays in-region, and RIVER manages everything.
- Customer Cloud (Private Deployment, RIVER Managed): deployed into your cloud environment with private networking controls (private endpoints, Key Vault, IAM/SSO), operated by RIVER within your security boundary.
- Customer-Managed: hosted and operated by your team, with RIVER providing implementation guidance and agreed support. Used where full operational control is mandatory.
For private deployments, infrastructure consumption is billed through your cloud subscription and RIVER's platform fee remains separate.
See Terms - Module D.
What are our Privacy Act responsibilities (NZ/AU)?
RIVER designs deployments to align with the New Zealand Privacy Act 2020 and, where relevant, the Australian Privacy Principles.
- You remain the data owner and are responsible for decisions about collection, retention and lawful use of personal information
- RIVER acts as a service provider, handling data only to deliver the agreed services
- You confirm you have obtained all necessary consents and have lawful basis for any personal data processed through the platform
- Access is controlled, logged, and restricted to authorised personnel and agreed purposes
For sensitive or health-related data, additional controls are commonly applied on top of standard encryption in transit and at rest: strict access logging, retention controls, and secure deletion and export processes.
See Terms - Clause 4.
Security
What security certifications does RIVER hold?
Our security and AI governance controls are aligned to three frameworks, with independent certification in progress:
- ISO 27001 (Information Security) - aligned, certification in progress. Our information security management system follows ISO 27001:2022 controls: risk-based security, access management, encryption, incident response, and continuous improvement.
- ISO 42001 (AI Governance) - aligned, certification in progress. Our AI management system follows ISO 42001:2023: AI risk assessment, data quality governance, human oversight, model lifecycle management, and responsible AI principles.
- SOC 2 Type II (Trust Services) - aligned, audit planned. Our controls align to SOC 2 trust service criteria: security, availability, confidentiality and privacy.
Insurance is covered separately below, and the full posture is on our Security and Governance page.
How do we ensure security and permission control?
Security controls depend on the deployment model, but commonly include:
- Role-based access control
- SSO and 2FA via your identity provider where available
- Audit logging of access and key actions, exportable where required
- Least-privilege access and separation of environments
- No access expansion without explicit approval
For Customer Cloud deployments, private networking and client security services can be used as part of the agreed architecture.
See Terms - Clause 4.
How are security incidents handled?
If RIVER becomes aware of a confirmed Security Incident affecting Customer Data within RIVER's control, we will notify you without undue delay and in any event within 48 hours of confirmation, provide updates and reasonable remediation steps, and document the incident and the response.
Specific audit log retention and reporting requirements are agreed in the Proposal where needed.
See Terms - Clause 4.
How is audit logging handled?
The audit logging specification is co-designed during engagement kickoff and documented as a governance schedule. The platform can log data that passes through the platform or the LLM, at the parties' collective discretion within the scope and budget of the engagement.
A typical audit trail includes the user or role and timestamp, the case reference and knowledge sources used, the model deployment identifier, the output reference, and the user action where that is implemented.
The specification captures key operational data while excluding sensitive data from logs, as agreed during co-design.
See Terms - Clause 4.
Ownership and exit
Who owns data, code, and IP?
You own:
- All client-provided data and content (documents, policies, SOPs)
- Customer Data, embeddings, logs, and AI outputs generated from your inputs
- Your business logic and operational workflows
RIVER owns:
- The RIVER platform IP and core delivery framework (Catalyst)
- Delivery methods and reusable components
- Generic improvements to the platform
You may operate your instance commercially without restriction, as described in the Proposal.
See Terms - Clause 6.
How can we access our code?
Your instance code - the modules, configurations and UI built for you - is available through a tiered access model:
- Code Visibility (read-only): inspect your codebase, run audits, show investors.
- Code Access (read-write): your in-house team can extend and modify instance code.
- Enablement: training for your developers on the framework, safe extension patterns and the deployment pipeline, available with Code Access.
Code access is for your employees and direct contractors during the engagement. A third-party development firm needs our prior written consent, and that restriction lifts once your instance is separated under Module F.
RIVER's core delivery framework (Catalyst) is always separated from your instance code. You get full access to what we built for you, and we retain the framework that powers it. Fees for code access are specified in the Proposal.
See Terms - Module E.
What if we want to part ways?
Your data and IP are always yours, and that does not change on exit.
Notice periods. Pilot: one month's written notice. Production: three months' written notice. Both apply after the minimum term, and engagements then continue month to month.
Early termination fee (committed terms only): where you agreed a committed term in exchange for a benefit, such as a discount or up-front work at no cost, ending it early costs 50% of the fees remaining for the balance of that term. Month-to-month and Pilot engagements carry no early termination fee.
Post-termination. On request, RIVER can keep a Production platform available in read-only mode for a transition period at reasonable cost, except where the engagement ended for material breach or non-payment. RIVER exports Customer Data in standard formats within 20 business days, and Customer Data is deleted within 30 business days of your deletion request.
See Terms - Clause 8.
Can we run it ourselves later, without you?
Yes, and the pathway is priced and real. If you want to fork and run your instance independently, there is a single Exit Licence Fee, typically around $50K and sized to your platform. It covers the three things you need:
- the Perpetual Instance Licence to keep using the Stripped Catalyst Core, so your platform runs on without us;
- the Separation Engineering to strip our core framework and package your instance as a standalone codebase, with dependency and deployment documentation;
- Training and Handover for your team, including one month of post-separation advisory support.
It can be paid as a lump sum or in instalments, and your scope and fee are confirmed in writing before work begins. If you want your team inspecting or extending the code first, we arrange ongoing code access separately, from $10K.
Independence is available where your Proposal grants it, once the Exit Licence Fee and any amounts due are paid. It is not available during a pilot, or while you are in breach.
See Terms - Module F.
Do you offer source-code escrow?
Because you hold the code and the perpetual licence survives us, escrow is not necessary to protect the continuity of your platform. Where your procurement requirements nonetheless call for a formal escrow arrangement, we will establish one at your cost.
See Terms - Module F.
Contract and liability
What are RIVER's liability limits?
RIVER's liability is structured in three tiers:
- General liability (negligence, service failure): the lesser of fees paid in the 12 months preceding the event, or NZD $500,000
- IP and confidentiality breach: NZD $1,000,000
- Fraud, wilful misconduct, death or personal injury: unlimited
Indirect, consequential, special and incidental losses, including loss of profits, revenue or goodwill, are excluded by both parties.
See Terms - Clause 7.
Do you hold insurance?
Yes. RIVER holds Technology Liability insurance covering Professional Indemnity and Errors & Omissions, Public Liability, Cyber Liability, and Statutory Liability.
Limits of liability are NZD $1,000,000 per the policy schedule. Cover extends to work performed by contractors and subcontractors engaged by RIVER Group. RIVER will notify you if coverage materially changes during an active engagement. Increased limits and certificates of currency are available on request.
See Terms - Clause 7.
How are disputes resolved?
Disputes are governed by New Zealand law, and the process follows:
- Executive escalation: 10 business days
- Mediation: via the Resolution Institute Standard Mediation Agreement, within 20 business days of failed escalation
- Court proceedings: neither party may begin until mediation has been attempted. Nothing prevents either party from seeking urgent interlocutory relief where necessary.
See Terms - Clause 9.
Have different ideas or requirements? We are always open for a kōrero.