hello@getrivet.ca and Rivet can produce additional attestation.
The short answer
As of June 24, 2026, all client information that Rivet stores at rest lives on Canadian infrastructure:The Twilio telephony layer (which records inbound calls in the moment they happen) is hosted in the United States. Twilio recordings are deleted at 30 days; SMS bodies and call records are deleted at 90 days. The Data Processing Agreement (v2.0, effective June 24, 2026) enumerates every sub-processor and its processing location.
- The database — every client phone number, voicemail transcript, conversation, audit log row, and account record — is hosted by Supabase in their
ca-central-1region (Montreal).- The voicemail greeting audio files (the outgoing prompts you record for callers, not client voicemail content) are hosted by Cloudflare R2 with an Eastern-North-America location hint that places them in Canadian data centres in normal operation.
- Voicemail transcription and intent classification run locally on Rivet’s Canadian hardware in Belle River, Ontario — no cloud AI service receives client audio or transcripts.
What changed on June 24, 2026
Before June 24, 2026, the database (Supabase) was hosted in a United States region. The page describing voicemail processing used to say “the database is currently hosted in a United States region” — it now says ca-central-1 because the migration is complete. Rivet executed a planned cutover that moved every existing client record, conversation, voicemail transcript, and audit log row from the US Supabase region toca-central-1. The migration was performed under a maintenance window, with row-count parity verification on every table, byte-identity verification on the sensitive fields (subaccount credentials, push credential identifiers), and a tested encrypted-transfer process (GPG-encrypted dump piped over TLS).
Your existing data — every voicemail transcript, every conversation, every audit row — was migrated. The Data Processing Agreement was updated to v2.0 to reflect the new sub-processor list and was presented to every signed-in practitioner for re-acceptance at next sign-in.
Where each kind of information lives
This table is the specific answer most College reviewers and compliance officers are looking for.
The pattern: persistent records are in Canada; in-transit delivery and the telephony layer touch other countries but don’t hold client content longer than necessary.
Evidence your reviewer can ask for
If a College auditor or compliance officer wants more than this page, here’s what Rivet can produce:1. Confirmation of the Supabase region
The Supabase region for Rivet’s project isca-central-1. This is verifiable in two ways:
- DNS lookup of
auth.getrivet.ca— Rivet uses a custom domain that points at the Supabase project. A reviewer can confirm the underlying Supabase project’s region from the Supabase dashboard project settings. Rivet will provide a screenshot of the project’s region setting on request. - API response headers — every Supabase REST API response includes a region indicator. Rivet can produce a captured response showing
ca-central-1on request.
2. Confirmation of the Cloudflare R2 bucket location
The R2 bucket name isrivet-greetings. The location hint is set to ENAM (Eastern North America), which targets Canadian and US east data centres. Rivet will provide a screenshot of the R2 bucket configuration on request.
If your reviewer requires strict Canadian-only object storage with a contractual guarantee, the alternative is AWS S3 in their Canadian region. Rivet considered this and chose the R2/ENAM path because the content stored is the outgoing voicemail greeting that callers hear — not client information. Persistent client information at rest is on Supabase ca-central-1 (strict Canada).
3. The Data Processing Agreement v2.0
The current DPA is published atdocs.getrivet.ca/privacy/data-processing-agreement (Rivet’s product guide). It enumerates every sub-processor and its processing location, the breach-notification timeline (72 hours), the retention schedule, and the service-scope description. The full DPA text — with its SHA-256 hash that proves you accepted what’s still there — is in your account, accessible under Settings.
4. The signed attestation letter
If your College requires a signed attestation from Rivet directly (rather than a pointer to the DPA), emailhello@getrivet.ca with the recipient name and the date you need it by. Rivet will produce a signed letter on company letterhead confirming the residency posture described on this page. Turnaround target: 2 business days.
5. The audit log of your account
Significant access events on your account are written to an append-only audit log. The events include practitioner sign-ins, voicemail playback, audio file fetches, outbound SMS dispatches, voice token mints, and DPA acceptance events. Rivet will produce an extract of your audit log on request — typically used in incident investigations rather than routine audits.What this lets you say
If a College auditor asks where your clients’ information is stored, the accurate, defensible answer is:
All persistent client information — voicemail transcripts, SMS conversation content, call records, clinical records (progress notes, assessment responses, risk assessments, and client record fields), audit logs, and practice records — is stored on Canadian infrastructure. Rivet’s database is hosted by Supabase in their ca-central-1 (Montreal) region. Voicemail audio at the telephony provider (Twilio, United States) is retained for 30 days and then deleted; SMS bodies and call records at Twilio are deleted at 90 days. Voicemail transcription and intent classification run on Rivet’s Canadian hardware in Belle River, Ontario — no cloud AI service receives client audio or transcripts. The Data Processing Agreement enumerates every sub-processor and its processing location.
This is the language Rivet recommends because every clause is verifiable. It does not overclaim (“nothing ever leaves Canada” would be wrong — telephony and push delivery touch other countries) and does not underclaim (“Canadian residency” is now accurate at rest, where it matters most).
What about cross-border data transfer concerns?
The two cross-border touches above are:- Twilio (United States) holding voicemail audio for 30 days. This is the telephony provider’s operational retention. Rivet’s worker fetches the audio from Twilio in Canada, transcribes it locally, and writes the transcript to the Canadian database. The original audio at Twilio is then deleted at 30 days by Rivet’s automated purge. Twilio operates under its own contractual data-handling commitments and is named in the DPA.
- Mobile push delivery via Apple and Google (United States). When Rivet pushes a notification to your phone, the payload is intentionally minimal — typically just an alert subject line. The actual content (voicemail transcript, message body) is fetched by your device over HTTPS from the Canadian database after you tap the notification. Apple and Google do not see client information in the push payload.
When this page changes
This page reflects the architecture as of the most recent material change. The Data Processing Agreement version is the canonical record — when sub-processors are added or removed, when a sub-processor’s processing location changes, or when retention defaults shift, the DPA gets a new version and you’re asked to re-accept. This page is updated in lockstep. The most recent material change was June 24, 2026 (the Supabase migration). Earlier material changes are listed in the changelog.Related articles
The Data Processing Agreement
The full sub-processor table, retention schedule, and breach-notification timeline.
Voicemail processing in Canada
Step-by-step path a voicemail takes from your client’s phone to your inbox.
Encryption
What’s encrypted at rest, in transit, and on your device.
Breach response
The 72-hour notification commitment in the DPA.
