ecomOS Platform
Functions
Platform Overview
Order Management
Product Data Master 
Feed Management
Tools
Dynamic Data Sync
AI Data Enhancement
Analytics & Insights
Automated Customs
Solutions
Use Cases
eCommerce
Marketplaces
Payment Facilitators
Fulfillment Services
Cross-Border Seller
Our Ecosystem
International Coverage
Our Partners
Explore
Documentation
API Reference
Help Center
Resources
Case Studies
Newsroom
Pricing
RIVAFY
About Us
Our Mission
Our Customers
Contact Us
People & Careers
Careers at RIVAFY
Explore opportunities
Let's talk
EN
ecomOS Platform
Functions
Platform Overview
Order Management
Product Data Master 
Feed Management
Tools
Dynamic Data Sync
AI Data Enhancement
Analytics & Insights
Automated Customs
Solutions
Use Cases
eCommerce
Marketplaces
Payment Facilitators
Fulfillment Services
Cross-Border Seller
Our Ecosystem
International Coverage
Our Partners
Pricing
Support
Explore
Documentation
API Reference
Help Center
Resources
Case Studies
Newsroom
Pricing
RIVAFY
About Us
Our Mission
Our Customers
Contact Us
People & Careers
Careers at RIVAFY
Explore opportunities
Let's talk
EN
Get started

Vulnerability Disclosure Program

Our vulnerability disclosure program embodies transparency, ensuring a clear and open process for reporting, acknowledging, and remediating security findings.

Last updated July 01, 2025

RIVAFY Vulnerability Disclosure Policy

In Short: RIVAFY's Vulnerability Disclosure Policy fosters trust and collaboration with security researchers. Report vulnerabilities responsibly via our form; RIVAFY will address them, and asks researchers to avoid harm and public disclosure until resolved.

Our Approach to Vulnerability Disclosure

At RIVAFY, we believe that effective disclosure of security vulnerabilities is built on a foundation of mutual trust, respect, transparency, and a shared commitment to the common good between RIVAFY and Security Researchers. Together, our collective vigilance and expertise enhance the ongoing security and privacy of RIVAFY's customers, products, and services.

Security Researchers

RIVAFY welcomes vulnerability reports from all sources, including independent security researchers, industry partners, vendors, customers, and consultants. For the purpose of this policy, RIVAFY defines a security vulnerability as an unintentional weakness or exposure that could potentially compromise the integrity, availability, or confidentiality of our products and services.

Scope

This policy applies to all digital assets owned, operated, or maintained by RIVAFY, including our public-facing websites.

Our Commitment to Researchers

  • Trust: We are committed to maintaining trust and confidentiality in all our professional interactions with security researchers.
  • Respect: We treat all researchers with the utmost respect and acknowledge your valuable contribution to keeping our customers safe and secure.
  • Transparency: We will collaborate with you to validate and remediate reported vulnerabilities, consistent with our dedication to security and privacy.
  • Common Good: We thoroughly investigate and address issues in a manner that prioritizes protecting the safety and security of those who might be affected by a reported vulnerability.

What We Ask of Researchers

  • Trust: We kindly request that you communicate any potential vulnerabilities responsibly, allowing sufficient time and providing adequate information for our team to validate and resolve the issues.
  • Respect: We ask that researchers make every effort to prevent privacy violations, avoid degrading the user experience, minimize disruption to production systems, and prevent data destruction during security testing.
  • Transparency: We request that researchers provide the necessary technical details and background to enable our team to accurately identify and validate reported issues, preferably using the designated form.
  • Common Good: We urge researchers to act for the common good, safeguarding user privacy and security by refraining from publicly disclosing unverified vulnerabilities until our team has had adequate time to validate and address the reported issues.

Vulnerability Reporting

RIVAFY recommends that security researchers share the details of any suspected vulnerabilities across any asset owned, controlled, or operated by RIVAFY (or that could reasonably impact the security of RIVAFY and our users) using the web form below. The RIVAFY Security team will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and then take appropriate action for resolution.

To submit your Report please use vulnerabilityreport@rivafy.com.

Join our newsletter

Stay up to date on product releases, industry news and useful tips for your successful journey

By subscribing, you agree to our Privacy Policy
ecomOS Platform
Order ManagementProduct Data MasterFeed ManagementDynamic Data SyncAI Data EnhancementAnalytics & InsightsAutomated CustomsIntegrations
ecomOS Platform
Order ManagementProduct Data MasterFeed ManagementDynamic Data SyncAI Data EnhancementAnalytics & InsightsAutomated Customs
Solutions
eCommerceMarketplacesPayment FacilitatorsFulfillment ServicesCross-Border SellerInternational CoverageOur Partners
Solutions
eCommerceMarketplacesPayment FacilitatorsFulfillment ServicesCross-Border SellerInternational CoverageOur Partners
Explore
API ReferenceHelp CenterCase StudiesNewsroomPricing
Explore
API ReferenceHelp CenterCase StudiesNewsroomPricing
RIVAFY
Our MissionOur CustomersContact UsCareers at RIVAFYExplore Opportunities
RIVAFY
Our MissionOur CustomersContact UsCareers at RIVAFYExplore Opportunities
© 2025 RIVAFY AG, Switzerland
‍
RIVAFY AG or its affiliates provide services under a license or registration in various jurisdictions. Money transmission services in Switzerland provided by RIVAFY AG. For more details, please contact us for regulatory information.
Terms and ConditionsService TermsCountry TermsPrivacy PolicyVulnerability Disclosure ProgrammDisclaimerLegal Notice
Code of ConductAccessibility StatementStatuspage