Security & Compliance

How we protect the Rivkor platform

True Bearing Safety Solutions hosts Rivkor as a web application served over HTTPS. The hosted service runs on Google Firebase (Google Cloud), including Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, and Firebase Cloud Functions (server-side logic that can perform privileged operations outside the browser).

Access to customer data in Firestore and Storage is enforced with Firebase security rules. Those rules require a signed-in user and apply company-scoped authorization using information carried in the user's identity token (for example, company membership and role-based permissions). Claim and permission updates are coordinated through Cloud Functions so enforcement stays consistent between the client and backend.

We use Firebase App Check with reCAPTCHA on production hosts to help reduce automated abuse and protect callable backend entry points. Where your organization enables it, sign-in can include multi-factor authentication through Firebase Authentication.

Data at rest and in transit for Firebase and Google Cloud is handled according to Google's platform security and compliance documentation. This page is a high-level description of our architecture—not a certification, audit report, or legal agreement.


Privacy & legal

For how we collect and use personal information, see our Privacy Notice & legal terms, along with our cookie and data processing documents linked from the site footer.

Contact

Questions about security or compliance can be directed to info@truebearingsafety.com. If you believe you have found a vulnerability, include enough detail to reproduce the issue and allow reasonable time for us to respond before public disclosure.