At a glance
Security claims should match the service you use. Here is what the current build does, what still needs verification, and how to raise a concern.
01Current service status
Riff is in development. The current workspace is designed for local use and does not yet provide public customer authentication. Public access to connected-account features requires further security and operational work.
This page describes safeguards present in the implementation and identifies what remains to be verified. It does not claim a security certification, independent audit, or Meta approval.
02Safeguards in the current build
- Server-side Instagram integration. Instagram access tokens are used by server-side publishing and insights code. Riff does not ask for your Instagram password.
- Encrypted API transport. The integrations with Meta, OpenAI, and Cloudflare R2 use HTTPS. This does not establish that every production storage system or customer connection has been secured.
- Separate media storage. Workspace assets use local storage or a private R2 bucket. Media selected for publishing is copied to separate public hosting for Meta to retrieve; that copy can be accessible to anyone who has its URL.
- File access boundaries. Local storage code confines file paths to the configured data directory. Application code includes project and asset ownership checks, which still need to be validated against real authenticated customers.
03Before public connected accounts
Production readiness requires verified customer authentication and account isolation, protected token storage and key management, a secure authorization and revocation flow, deletion handling, retention and backup controls, and an incident response process. These controls must be tested before customer accounts are onboarded.
Riff is not currently making claims of encryption at rest across all systems, around-the-clock monitoring, a completed penetration test, SOC 2 or ISO certification, or a guaranteed incident response time. The page will be updated as safeguards are implemented and verified.
04Report a security concern
A public contact address has not been confirmed yet. If you already work with the Riff team, use your existing contact to make this request. A monitored public address must be added before these pages are finalized.
For a report, include the affected page or feature, a short description, steps to reproduce using an account you control, and the potential impact. Redact other people’s information and credentials. Do not include passwords, access tokens, or app secrets.
Please avoid accessing other people’s data, disrupting the service, or publishing exploit details before the team has had an opportunity to investigate. This page does not authorize testing third-party systems.
05Incident response
The production response process must provide for investigating reports, containing unauthorized access, correcting the cause, and notifying affected people, regulators, and Meta when required. Meta-related incidents must be handled under the notification requirements in Meta’s Platform Terms.
A monitored reporting address and the internal response process must be in place before this draft is finalized.
06Protecting your account
Use strong account security and two-factor authentication on Instagram and any connected platform. Grant access only to accounts you are authorized to manage. Review publishing instructions, remove access you no longer need, and avoid uploading unnecessary sensitive information.
For access, correction, or deletion requests, see the Privacy Policy and Data deletion page.