FAQ
What is Rivaro?
What do you mean by "governance control plane"?
Rivaro does not deploy, run, or sell agents. It governs what happens when agents -- deployed by whatever stack your team chose -- cross the boundary. One governance layer across every runtime. Signed proof of every decision.
Think of it as the system of record for the agent estate: what agents you have, what they're doing, what's healthy, what's drifting, and a tamper-evident audit trail for every decision they made. Your runtime providers (Bedrock, Foundry, Vertex, homegrown frameworks) do the deploying. Rivaro is the layer above them.
What's the difference between a control plane and a runtime?
The runtime deploys and runs agents. The control plane governs what they do when they run. Different jobs, often different vendors.
Is this an AI firewall?
No. Firewalls are perimeter defenses. Rivaro is an inline governance layer that understands agent context: who the agent is, what it's trying to do, what policy applies, and whether the outcome matched the intent.
Is this a prompt guardrails library?
No. SDK-level guardrails sit inside one application and protect its prompt layer. Rivaro is a network-layer governance plane that sees every agent, every framework, and every tool call across your estate -- without code changes to the agents.
How is this different from my cloud provider's built-in agent governance?
In-ecosystem control planes govern agents inside their own cloud or runtime. They cover the agents they deployed. Rivaro is vendor-neutral by architecture -- one instance governs agents across any provider, any runtime, any framework, with one policy engine and one audit trail. See How Rivaro Works for the architecture.
How is this different from posture or discovery tools?
Discovery tools tell you what AI exists in your environment and assess its risk. Rivaro enforces policy in the request path at runtime. Different jobs, often complementary -- discovery finds the agents, Rivaro governs what they do.
Architecture and Operations
What's the latency overhead?
On Rivaro Cloud, expect ~150–200ms of gateway overhead for ingress detection, policy evaluation, and session management. On a local install, overhead is significantly lower because all services are on the same machine with no network hops. In both cases, the LLM provider's response time (typically 500ms–2s+) dominates total request duration.
For streaming responses — which is most real agent usage — the overhead is ingress-only. Once the LLM starts producing tokens, they stream through unblocked. Egress detection runs on the accumulated response after the stream closes.
Sidecar enforcement checks on tool calls add tens of milliseconds per call.
What happens if Rivaro is unreachable?
Configurable. Default: fail-open (traffic passes through, enforcement skipped, event logged). For high-sensitivity workloads: fail-closed (request rejected until governance is restored).
Does this work with streaming?
Yes. Streaming is fully supported for all providers. Egress detection runs on the accumulated response after the stream completes.
What data does Rivaro see and store?
See the Security & Trust page. Short version: scans request/response content for detection, stores detection metadata and policy decisions, discards raw prompts/completions by default.
How long does integration take?
Two code changes: base_url and an X-Detection-Key header. Most teams are routing traffic in under 5 minutes for the LLM proxy path. The sidecar (tool enforcement) is a single environment variable.
What frameworks does Rivaro work with?
Any framework that makes HTTP calls to an AI provider or external tool. Includes LangChain, CrewAI, AutoGen, Vercel AI SDK, raw OpenAI/Anthropic/Bedrock/Vertex/Azure SDKs, and MCP. See Agent Frameworks for integration snippets.
Does Rivaro govern MCP tool calls?
Yes. MCP tool invocations are governed at the outbound HTTP layer through the agent sidecar. See MCP Governance.
Can I run Rivaro in observe mode before enforcing?
Yes. By default, with no policies configured, Rivaro runs in observation mode -- detect and log without blocking. You decide what to enforce after seeing what your AI traffic actually looks like. See Enforcement & Policies.
How does Rivaro enforce policy on tool calls?
The agent sidecar evaluates every outbound tool call against the agent's identity, your policy rules, its budget, and its authority envelope before the call executes. If any of those rejects the action, the tool call never reaches the downstream system. High-risk actions can be held for human approval (DEFER). See Enforcement & Policies — Sidecar Enforcement.
Can Rivaro enforce budget limits on AI spend?
Yes. Budget enforcement is a gate in the enforcement chain, not a reporting layer. You set spend limits at three hierarchical scopes -- organization, department, and agent -- and Rivaro will WARN, THROTTLE, or BLOCK actions when spend approaches or exceeds thresholds. Cost data is captured on every request regardless of whether budget policies are configured, so you get spend visibility even before you set limits. See Budget & Cost Management.
Does Rivaro track what happens after an action executes?
Yes. Enforcement decides whether an action is allowed; outcomes track what happened after it ran. Rivaro verifies agent claims ("I refunded $50") against actual tool responses (the payment API returned $500) and flags mismatches. For multi-agent systems, the full delegation chain is tracked so accountability traces back to the originating agent. See Outcomes & Traceability.
What happens when an agent repeatedly violates policy?
Every actor (agent, user, API key) has a trust score (0–100). The score decreases as violations accumulate and recovers over time. Based on risk level, Rivaro can automatically escalate: warn, rate-limit, quarantine (all requests blocked until admin review), or terminate. Automatic escalation can be enabled or disabled per organization. See Enforcement & Policies — Agent Governance.
Compliance and Regulatory
Does Rivaro help with EU AI Act / FFIEC / HIPAA / SOX / Colorado AI Act compliance?
Yes, by producing the audit evidence and policy enforcement records that auditors and examiners require. The Colorado AI Act (effective June 30, 2026) adds requirements for impact assessments and risk management for high-risk AI systems -- Rivaro's governance decision history, detection taxonomy, and ActionRecord ledger provide the evidence base for compliance. See the Security & Trust page for the full regulatory crosswalk.
Where can I deploy Rivaro for regulated workloads?
Full self-hosted deployment in your VPC is supported, with the data plane entirely under your control. See Security & Trust -- BYOC for details.
What audit evidence does Rivaro produce?
Every enforcement decision produces a cryptographically signed AARM receipt (Ed25519, browser-verifiable, hash-chained). Not logs -- cryptographic proof. Auditors and examiners can verify receipts offline.
Competitive Positioning
Rivaro is evaluated against different categories of products depending on where the prospect is starting from. The honest answer differs by tier.
Tier 1: Direct head-to-head
How is Rivaro different from AgilePoint NX?
AgilePoint is a process-automation vendor since the 2010s that added an "AI Control Tower" bolt-on. Their governance is mediated by their process orchestration layer -- you govern an agent by routing it through an AgilePoint workflow.
Rivaro's governance is inline at machine speed, at the network boundary, with no orchestration layer required. Every enforcement decision produces a cryptographically signed AARM receipt (Ed25519, browser-verifiable, hash-chained against the previous receipt). AgilePoint publishes no comparable receipt format or verification tooling.
If your auditor or examiner needs signed cryptographic proof of every agent decision -- not workflow logs -- that's the difference.
Tier 2: "Why not my cloud provider's built-in governance?"
This is the most common objection from regulated mid-market buyers. The architectural answer applies to all hyperscaler control planes: they govern agents inside their own ecosystem.
How is Rivaro different from Microsoft Agent 365 / Entra Agent ID?
Agent 365 governs agents inside Microsoft Foundry, Copilot Studio, and the M365 surface. If your agents also run on Bedrock, OpenAI direct, Anthropic direct, LangChain, CrewAI, or homegrown frameworks, Agent 365 sees a fraction of your estate.
Rivaro governs all of them through one proxy and one policy engine. The honest question to ask yourself: what percentage of your agents are inside Microsoft Foundry vs. outside? If the answer is "all of them, forever," Agent 365 may be enough. If not, you need a vendor-neutral plane.
How is Rivaro different from AWS Bedrock AgentCore?
AgentCore governs AgentCore-native agents with strong Cedar-based policy. Agents running on EC2, EKS, or Lambda that use OpenAI or Anthropic SDKs without AgentCore are outside its scope.
Rivaro governs all of them -- AgentCore-native, EC2-deployed, Lambda-deployed, third-party-SDK-deployed -- and produces signed audit receipts that go beyond CloudTrail logs. CloudTrail tells you that an API call was made; AARM receipts tell you what agent made it, what context it was in, what policy was evaluated, and what decision was rendered, all cryptographically signed.
How is Rivaro different from Google Gemini Agent Platform?
Strong SPIFFE-based agent identity for Vertex-native agents. Same architectural pattern as the others: GCP-only scope.
Rivaro signs the action record itself, not just the identity that authorized the action. That's a different audit primitive -- you can prove what was done, not just who was allowed to do it.
We're multi-cloud. Can Rivaro govern all of it?
Yes. One Rivaro instance governs agents across AWS, Azure, GCP, on-prem, and any framework. That is the entire point of a vendor-neutral control plane.
Tier 3: "Isn't this what Kore.ai / IBM watsonx Orchestrate does?"
How is Rivaro different from Kore.ai / IBM watsonx Orchestrate?
They sell agents. We do not. Gartner's own AMP research explicitly states that the control plane cannot be owned by the same vendor that sells the agents, or the governance layer becomes a sales channel for the runtime.
Kore.ai is an agent runtime that retrofitted governance. IBM watsonx Orchestrate is an agent-building platform that added a governance layer. Rivaro is a governance plane that works with any agent runtime -- including theirs, if that's what your team chose.
Tier 4: Posture and discovery tools
How is Rivaro different from Zenity / Noma?
Posture and discovery tools tell you what AI exists in your environment and assess its risk -- they scan, inventory, and rate. Rivaro enforces policy in the request path at runtime, before actions execute.
Different jobs, different buyers, often complementary. Many organizations will run both: discovery to find the agents and rate them, Rivaro to govern what they do once found.
Tier 5: Prompt guardrails, AI gateways, MCP gateways
How is Rivaro different from Lakera / Guardrails AI / prompt-layer tools?
SDK-level guardrails are controls developers add to their own code, scoped to the prompt and response layer of one application. They protect a single application boundary.
Rivaro is a network-layer governance plane that works across all applications, all frameworks, and all tool calls without code changes. Guardrails libraries are one layer of defense inside a governed application; the control plane is where policy is defined and enforced across the entire agent estate. They coexist -- Lakera in the prompt, Rivaro at the boundary.
How is Rivaro different from a WAF / DLP / CASB?
Traditional security tools see network traffic without agent context. They don't know that an outbound HTTP call is a tool call, made by a specific agent identity, in service of a specific user request, accumulating context from previous actions in the session.
Rivaro does -- and enforces policy based on that context. A WAF can tell you traffic happened. Rivaro can tell you what agent did what, why, with what authorization, and produce a signed receipt of the decision.
Commercial
What does pricing look like?
Per-agent, per-month. Design partner terms available for early adopters. Contact us.
Can I try it for free?
Yes -- two paths. Sign up for Rivaro Cloud for the fastest onboarding (no installation), or run Rivaro locally with Docker. Observe mode (detect and log without enforcing) is free on both.
Should I use Rivaro Cloud or self-hosted?
Most teams start with Rivaro Cloud for evaluation and early production -- it has the smoothest onboarding. Self-hosted is recommended for regulated industries (financial services, healthcare, insurance, government) with data residency requirements, or for any team that cannot route production AI traffic through a third-party. Both run the same product; you can switch deployment models later without code changes. SOC 2 Type I for the cloud offering is in progress (Q3 2026 target) -- see Security & Trust.
How do I get a demo?
Request a conversation -- demos are scoped to your industry and walked through with a working agent in your sector (financial services, healthcare, insurance, SaaS, government).