Skip to main content

Security & Compliance

RIFT is built for teams whose publishing decisions get audited — human approval on every AI action, a complete version record, and infrastructure that answers hard questions before you're asked. See the full /featuresfeature set→ or request access below.

Human Approval

Nothing Ships Without a Named Reviewer

Every AI agent action in RIFT — drafting a page, editing a component, proposing a link — produces a change-set, not a live edit. A named person on your team reviews, edits, or rejects it before it reaches the public site.

Audit Trail

The Record Auditors Ask For

Every content item carries full version history — what changed, when, and who approved it. Policy pages and disclosures can show their entire publication history on demand.

Accessibility

Section 508 / WCAG Scanning Built In

Accessibility scanning runs as part of the platform itself, with audit reports generated automatically — not a third-party plugin bolted on after a complaint arrives.

Every AI Action, Reviewed by Name

Change-Sets

The Approval Gate Is Structural, Not Optional

There is no agent path that bypasses review. Every draft, edit, or proposed link an AI agent makes is staged as a change-set and routed to a named human before it can touch the live site — approve, adjust, or reject, every time. Learn more →

Audit Trail

Every Change, Attributed and Timestamped

Every content item retains its complete version history for the life of the page. When an auditor asks what was published on a disclosure page and when it changed, the answer is a lookup — not a reconstruction project. Learn more →

Git-Native

Every Publish Is a Commit

Publishing pushes a versioned commit to your own GitHub repository, deployed to Cloudflare, Netlify, or Vercel — whichever you already trust. No proprietary hosting, no lock-in.

Decoupled

The CMS Can Go Down. Your Site Can't.

RIFT publishes static files. Your live site doesn't run on RIFT — it's already deployed. A CMS outage, upgrade, or migration never takes your public site offline.

Complete Trail

A Publish History You Can Show an Auditor

Every publish, edit, and rollback runs through a versioned API with audit logging and idempotency keys — trace any change end-to-end, months or years later. Learn more →

AI That Stays Inside Your Perimeter

Instance-Configured

You Choose the AI Provider

RIFT's AI routing is configured per instance, not fixed in the platform. On self-hosted government deployments, no content or prompts leave your environment to an external provider unless you explicitly wire one in. Learn more →

Provider Control

Same API, Your Infrastructure

The versioned API and MCP tools your agents use route entirely within your deployment boundary — configure providers, review call logs, and audit every request without traffic crossing into a third-party service. Learn more →

Ready to see it evaluated against your own compliance requirements?

Request Access