About Rivault
Rivault is a security tool that lets users approve AI agent access to sensitive data through Face ID or passkey authentication. It stores details like passport numbers and credit card info in a zero-knowledge vault, so the service itself never sees the raw data. When an agent requests information for a task, Rivault sends an auth request, and after the task completes, the data is deterministically redacted from the agent's session, screenshots, and logs.
Review
Rivault addresses a specific friction in computer-use agent workflows: the need to hand over sensitive credentials without leaving them exposed in session logs or context windows. The tool introduces a human-in-the-loop approval step that interrupts the agent until the user unlocks the required data with Face ID or a passkey. With deterministic redaction after the task, it aims to limit where sensitive values can persist.
Key Features
- Zero-knowledge vault: Rivault stores data encrypted so that the service itself cannot access it.
- Group auth requests: The agent consolidates all needed data at a step, and the user reviews and approves the batch with Face ID or a passkey.
- Time-bound data access: Approved data gets a lifespan tied to the task session, and can be reused within that session without re-approval.
- Deterministic redaction: At task completion, timeout, or cancellation, the tool removes sensitive values from agent memory, screenshots, and every trail across supported platforms.
- Intent visibility: During auth, the user sees why the agent is requesting each data field, helping to catch prompt injection attempts before approval.
Pricing and Value
Rivault is listed as free on its Product Hunt page. No pricing tiers or plans have been announced at launch.
Pros
- The vault is zero-knowledge, so Rivault never holds plaintext sensitive data.
- Redaction is not limited to storage; it also covers screenshots and agent-side traces.
- Group auth allows auditing multiple data requests at once, reducing interruption frequency.
- Time-bound access limits the window where sensitive data is exposed.
Cons
- Approval requires the user to be available in real time, which can stall a task if the user is not present to respond.
- After unlock, the agent still receives the raw credential rather than working with a reference, so a prompt injection post-approval could still extract the value.
- Not suited for users who need to protect unstructured free-text sensitive information, as the tool's redaction currently targets structured data fields.
Rivault fits workflows where users run AI agents on tasks that involve structured credentials-like booking flights or filling forms-and want to avoid leaving those values in agent logs. It's less applicable when the primary risk is a compromised local device or when the sensitive data is freeform text without a predictable pattern. The tool's current free availability may change as development continues, and the roadmap includes experiments with more complete credential isolation.
Open 'Rivault' Website
Your membership also unlocks:








