Skip to content
Riff← Back to Riff

Riff / Legal & trust

Security

A straightforward view of how Riff handles access, protects content, and prepares for public connected accounts.

Draft updated September 7, 2026

PrivacyTermsSecurityData deletion
Draft for review

These pages are being prepared for Riff’s launch. The operating entity, public contact details, and production data practices still need confirmation. They are not yet final policies or a statement of Meta approval.

On this page

  1. Current service status
  2. Safeguards in the current build
  3. Before public connected accounts
  4. Report a security concern
  5. Incident response
  6. Protecting your account

At a glance

Security claims should match the service you use. Here is what the current build does, what still needs verification, and how to raise a concern.

01Current service status

Riff is in development. The current workspace is designed for local use and does not yet provide public customer authentication. Public access to connected-account features requires further security and operational work.

This page describes safeguards present in the implementation and identifies what remains to be verified. It does not claim a security certification, independent audit, or Meta approval.

02Safeguards in the current build

  • Server-side Instagram integration. Instagram access tokens are used by server-side publishing and insights code. Riff does not ask for your Instagram password.
  • Encrypted API transport. The integrations with Meta, OpenAI, and Cloudflare R2 use HTTPS. This does not establish that every production storage system or customer connection has been secured.
  • Separate media storage. Workspace assets use local storage or a private R2 bucket. Media selected for publishing is copied to separate public hosting for Meta to retrieve; that copy can be accessible to anyone who has its URL.
  • File access boundaries. Local storage code confines file paths to the configured data directory. Application code includes project and asset ownership checks, which still need to be validated against real authenticated customers.

03Before public connected accounts

Production readiness requires verified customer authentication and account isolation, protected token storage and key management, a secure authorization and revocation flow, deletion handling, retention and backup controls, and an incident response process. These controls must be tested before customer accounts are onboarded.

Riff is not currently making claims of encryption at rest across all systems, around-the-clock monitoring, a completed penetration test, SOC 2 or ISO certification, or a guaranteed incident response time. The page will be updated as safeguards are implemented and verified.

04Report a security concern

A public contact address has not been confirmed yet. If you already work with the Riff team, use your existing contact to make this request. A monitored public address must be added before these pages are finalized.

For a report, include the affected page or feature, a short description, steps to reproduce using an account you control, and the potential impact. Redact other people’s information and credentials. Do not include passwords, access tokens, or app secrets.

Please avoid accessing other people’s data, disrupting the service, or publishing exploit details before the team has had an opportunity to investigate. This page does not authorize testing third-party systems.

05Incident response

The production response process must provide for investigating reports, containing unauthorized access, correcting the cause, and notifying affected people, regulators, and Meta when required. Meta-related incidents must be handled under the notification requirements in Meta’s Platform Terms.

A monitored reporting address and the internal response process must be in place before this draft is finalized.

06Protecting your account

Use strong account security and two-factor authentication on Instagram and any connected platform. Grant access only to accounts you are authorized to manage. Review publishing instructions, remove access you no longer need, and avoid uploading unnecessary sensitive information.

For access, correction, or deletion requests, see the Privacy Policy and Data deletion page.

Riff

An AI head of marketing for people who don’t have one.

Product
How it worksPricing
Company
AboutCareersContact
Legal
PrivacyTermsSecurityData deletion
© 2026 Riff