Start with Rivaro
Rivaro is the governance control plane for AI agents. It enforces policy before agents act, detects risks across every request, and produces a cryptographic audit trail of every decision. Works with any framework, any provider, any runtime.
Rivaro can run locally, in Rivaro Cloud, or in your own infrastructure. Choose the path that matches how you want to evaluate or deploy it.
Choose where Rivaro runs
Run Rivaro locally
Local evaluation installs are currently set up together with our team as part of guided onboarding. Contact us to schedule a walkthrough.
Use hosted Rivaro
Create or join a workspace in Rivaro Cloud. Connect agents, configure policies, and view the decision ledger — Rivaro hosts everything.
Self-host Rivaro
Deploy Rivaro inside your own infrastructure for regulated or production environments — VPC, air-gapped, or data residency requirements. Contact us for deployment assistance.
Integrate your agents
Once Rivaro is running (locally, hosted, or self-hosted), connect your agents:
- Agent Frameworks — LangChain, CrewAI, Vercel AI SDK, AutoGen, and any OpenAI-compatible client
- Provider Guides — OpenAI · Anthropic · Azure OpenAI · AWS Bedrock · SageMaker · Vertex AI · Slack · Stripe MCP
- MCP (Model Context Protocol) — Govern MCP tool calls with detection-key auth and path-based delegation
- Error Handling — Rivaro-specific errors, retry strategies, debugging enforcement decisions
Configure governance
- Configuration Guide — AppContexts, detection keys, rate limits, allowed models, organization settings
- Enforcement & Policies — Observation vs enforcement, policy actions, rule matching, sidecar enforcement chain, agent governance
- Budget & Cost Management — Budget policies, spend enforcement, cost intelligence
- Policy Templates — Thirteen pre-built templates from healthcare and financial to zero-trust and sandbox
- Policy Scoping — Detection type, risk category, capability surface, boundary surface, intent class
- Policy Bundles — Export, import, dry-run, prune — GitOps for policy
- Authority Envelopes — Per-actor autonomy contracts with freeze / thaw kill switch
- Notifications & Integrations — Slack, SIEM, PagerDuty, and OTLP telemetry export
Detect & govern
- Detection Engines & Stability — Built-in detectors, Presidio / Google DLP / Comprehend, pattern sources, suppression
- Drift Monitoring — Prompt drift and content drift detection
- Document Toolkit — Schemas, catalogs, rule packs, conformance receipts; plus output checks
- Training-Data Connectors — S3, GCS, Azure Blob, Database — TRAINING-stage detection
Platform & operations
- Discovery & Shadow AI — Find ungoverned agents, MCP servers, and shadow LLM usage
- Asset Management — Approve, deny, promote discovered assets to governed entities
- Agent Management — Identity, ownership, dependencies, blast radius
- Sessions — Per-conversation timeline of detections, decisions, and outcomes
- Outcomes & Traceability — Action verification, claim detection, delegation tracking
- Actor Governance — Trust scores, automatic quarantine / termination
- Incident Management — Triage, investigate, resolve, mitigate
Compliance & reporting
- Compliance Reporting — SOC 2, HIPAA, PCI DSS, GDPR, CCPA, ISO 42001 evidence packages
- Executive Reporting — Governance score, executive board view, guardrail summary, cost overview
- AI Bill of Materials — CycloneDX and SPDX exports per agent
Reference
- Understanding Detections — 8 risk domains, 17 risk categories, 60+ detection types
- How It Works — Architecture, detection pipeline, enforcement surfaces, AARM receipt chain
- Security & Trust — Cryptographic audit trail, Ed25519 receipts, AARM alignment
- FAQ — Common questions, competitive positioning, objection handling
- API Reference — Full OpenAPI specification for all proxy endpoints