Skip to content

Data boundary

You only ever see findings about your own organisation.

The alerts, evidence and reports in your account concern your monitored domains, your people and your organisation. Nothing in Rivanorth Oko shows you another customer’s alerts.

You see the risk a third party poses to you: their risk level, their score and the alerts that concern you. You never see their raw findings, their credentials or their people’s data.

The same rule applies in reverse. An organisation that lists you as a third party sees only the risk you pose to them, never your raw findings.

Before an account is opened, Rivanorth verifies who the organisation is and who is asking, a Know Your Customer check. Access to findings is limited to verified owners of the domains being monitored. That is what makes it possible to show third-party risk to everyone without exposing anyone’s data.

Emails, Inbox items and webhook events tell you that something was found and link you to it. The exposed data itself is only visible after you sign in.