🔍
Press ESC or click to close
⚡ Latest
Loading latest reviews…

Rivault Review 2026: Can You Really Trust AI With Your Passport & Card Details?

✏️ Mahmoud Salamoun · August 05, 2026 · 5 min read
Rivault Review 2026: Can You Really Trust AI With Your Passport & Card Details?
AI Agents AI Agent Infrastructure Week-Old Launch Updated Aug 2026

Rivault Review 2026: A Passkey-Gated Vault for Letting AI Agents Use Your Sensitive Data

Rivault scores 5.8/10 in ToolRadar's independent review — a passkey-gated, zero-knowledge vault that lets AI agents use your passport, credit card, and other sensitive data without you typing it in, tested against its official site and its Product Hunt launch this week.

August 4, 2026 · 8 min read · AI Agents

Reviewed by the ToolRadar editorial team, based on the company's official site and its Product Hunt launch thread.

1 wkSince Public Launch
103Product Hunt Followers
SoloBuilt by One Founder
$0Current Price

Rivault is trying to fix a specific, uncomfortable moment: an AI agent is booking your flight or filling out a form, and it asks you to type in your passport number, your credit card, or your SSN directly into a chat window. After going through the company's official site and the questions raised during its Product Hunt launch this week, ToolRadar found a reasonable technical approach to a real problem — built by one person, one week old, and asking for a level of trust that a week-old, solo project hasn't yet earned for data this sensitive.

The mechanism: you store sensitive items — passport number, card details, insurance info, dietary preferences, whatever an agent might need — in a vault encrypted on your own device before it ever reaches Rivault's servers. When a connected AI agent needs an item to complete a task, Rivault sends you an authorization request; you approve it with Face ID or a passkey, the agent gets exactly that item for that task, and the data is deterministically redacted afterward. Rivault says it never has default access to your data. It connects to Claude, ChatGPT, and other agents through an API key or MCP, similar in spirit to how ToolRadar found an AI agent handles browsing the web on your behalf — the agent gets just enough access to do the job, nothing standing. This review covers what the vault actually protects, a sharp question a launch-day commenter raised that goes right at the model's weak point, and why the newness here matters more than usual.

"The vault is the easy half of this problem — and the maker knows it."

What Is Rivault?

Rivault is a zero-knowledge data vault built specifically for AI agents and computer-use agents (CUAs) that need sensitive personal information to complete real-world tasks — booking a flight, checking out with a saved card, refilling a prescription, making a restaurant reservation. Instead of typing that data into a chat window where it can sit in session logs and model memory, you store it once in Rivault, encrypted on your device with a key derived from your passkey. Rivault's own servers only ever see ciphertext. When an agent needs an item, you get a real-time authorization request showing exactly what's being accessed and why; approve it with Face ID or your passkey, and the agent receives that one item for that one task. It's built by a single founder, Hyu Lim, and launched publicly on Product Hunt this week with 103 followers and 114 upvotes so far.

💡 Quick Context: Rivault launched on Product Hunt this week, built solo by founder Hyu Lim. As of this review it has no written reviews on Product Hunt or G2, no published pricing tiers, and no public security audit.

Pros and Cons

✓ What Works

  • ✅ Zero-knowledge encryption on-device is the right default for data this sensitive, and matches patterns established password managers already use
  • ✅ Per-task, Face ID/passkey-gated authorization instead of standing agent access to your full vault
  • ✅ Free to use today, with a genuinely lower-friction alternative to retyping sensitive data into every new agent session
  • ✅ Per-item access rules let you decide what needs ad-hoc authorization and what doesn't

✗ What to Watch For

  • ❌ One week old, built by a single founder, with no written reviews on Product Hunt or G2 yet and no public independent security audit to point to
  • ❌ A real commenter's sharpest criticism at launch — that securely storing data is only half the problem, and what the agent itself does with that data on the other side is the harder, unsolved part — didn't receive a detailed public response
  • ❌ No published pricing beyond free, so there's no way to evaluate what a sustainable business model looks like for a company holding this category of data

Key Features

🔐

Zero-Knowledge Vault, Encrypted Before It Leaves Your Device

Every item you store — passport number, card details, health history, travel documents — is encrypted on your device with a key derived from your passkey before it's ever sent to Rivault's servers. The company states its servers only ever see ciphertext, and that even Rivault itself can't decrypt a Face-ID-protected item; decryption happens locally, either in the Rivault desktop app or the agent's own runtime. This is a standard and reasonable pattern for this category (1Password and other password managers use similar zero-knowledge designs), and it's the right default for data this sensitive — the open question, which the product's own newness leaves unanswered, is how that design holds up once it's been through independent security review rather than just a launch-week product description.

Per-Task Authorization With Face ID or Passkey

Rather than granting an agent standing access to your vault, Rivault triggers a specific authorization request every time an agent needs an item, showing what's being requested and for what task, and you approve with Face ID or a passkey in the moment. Approved items are deterministically redacted after the task completes, so the data doesn't linger in the agent's context, session logs, or model memory afterward. This request-and-approve pattern is a meaningfully more cautious design than a blanket API key that hands an agent everything up front, and it echoes the same principle ToolRadar found valuable when testing what happens when an AI agent gets full standing control of an inbox — narrow, task-scoped access beats broad standing permission every time sensitive data is involved.

🔗

One-Click Connection via API Key or MCP

Rivault connects to OpenClaw, Claude, ChatGPT, or, per the company, any AI agent, through either an API key or MCP, and the company advertises this as a one-click install with no code required. Once connected, the flow the site demonstrates is booking a flight: the agent asks for name, date of birth, passport number, and seat preference, and instead of you typing each field into the chat, you authorize the whole request through Rivault in one tap. It's a genuinely lower-friction pattern than the current default of retyping sensitive fields into every new agent session, provided the underlying trust in a week-old, solo-built vault holds up.

📄

User-Defined Access Rules Per Item

You decide, per vault item, whether it requires ad-hoc authorization every time or can be accessed more freely by connected agents — a dietary preference might not need a Face ID prompt every time a restaurant-booking agent checks it, while a passport number or credit card reasonably should. This granularity is a sensible design choice, putting the judgment call about what's actually sensitive in the hands of the person who owns the data rather than a one-size-fits-all policy. It's also, like everything else here, a promise made by a one-week-old product rather than a pattern that's been tested against real misuse yet.

Rivault vs. Competitors

Tool Best For Pricing Maturity
Rivault Purpose-built vault for AI agents & CUA tasks Free, no paid tiers published Week-old, solo-built, no reviews yet
1Password General password & data management Paid plans, no free tier Established, 4.8/5 (45 PH reviews)
Piiano Vault Developer-focused PII/PCI/PHI vault via API Custom, developer-oriented pricing 5.0/5 (7 PH reviews)

Setup and Learning Curve

Setup is genuinely quick based on the company's own walkthrough: sign up with your email, register a passkey (which becomes the only key to your vault, never stored by Rivault itself), add the personal data and context you want available, and connect it to Claude, ChatGPT, or another agent via API key or MCP in one click. There's no live independent account of this process from an outside reviewer yet, since the product launched days ago — everything about the setup experience described here comes from the company's own site, not a tested third-party account.

💡 The One Question That Actually Matters Here

"the vault is the easy half of this problem, and I suspect you already know that"
— An unnamed Product Hunt commenter · Product Hunt Launch Thread
"I created Rivault to solve for the friction and worry of typing in sensitive details"
— Hyu Lim, founder · Product Hunt Launch Thread
"no sensitive data stored in session logs and memory"
— Hyu Lim, founder · Product Hunt Launch Thread

Who Should Use Rivault?

Best For: Individuals who already lean heavily on AI agents and computer-use agents for real tasks — travel booking, online checkout, appointment scheduling — and who are comfortable being an early, hands-on tester of a solo-built security tool in exchange for not retyping sensitive data into every chat.

Consider an Alternative If: You're not comfortable handing SSNs, passport numbers, or card details to a week-old, unaudited, single-founder product regardless of its stated encryption design, you want a vault with an established track record like 1Password, or you'd rather wait for Rivault to publish a security audit and gather real independent reviews before trusting it with this category of data.

Rivault Pricing

Plan Price What's Included
Personal (Current) Free Vault storage, Face ID/passkey auth, MCP and API key connections
Paid Tiers Not yet published No paid plan is listed as of this review
Setup Cost $0 Sign up with email and register a passkey, no card required
Try Rivault Free →

ToolRadar has no affiliate relationship with Rivault — the link above goes directly to the official site.

Expert Editorial Opinion

🧠
ToolRadar Editorial Team
AI Agents Coverage

The core cryptographic design here is sound and unsurprising — client-side encryption before data reaches a server, a passkey-derived key the vendor never holds, per-task authorization instead of standing access. None of that is novel; it's the same playbook established password managers use, applied to a new problem (agent-readable sensitive data) rather than a new solution to an old one.

The most important thing said in this entire launch wasn't from the founder — it was the pushback. A launch-day commenter told the founder directly that the vault is the easy half of this problem, and the founder didn't dispute it. Storing data safely and controlling who's allowed to read it is a solved problem in security engineering. What's much less solved is what happens after an agent is granted an item: does it hold that passport number in its own context window longer than necessary, could a prompt injection trick the agent into requesting or exfiltrating an item it shouldn't, and how would you even audit that after the fact? Rivault's current design addresses the storage half convincingly. It doesn't yet have a public answer for the agent-behavior half, which arguably matters more.

This arrives during a moment when the broader industry is pouring serious money into exactly this class of problem — AI security startup Glow raised $180 million to police what AI agents and tools are allowed to do on corporate devices in the same weeks Rivault launched with a single founder and no funding disclosed. That contrast isn't a knock on Rivault's idea — a personal vault and enterprise endpoint security are different problems — but it's a useful reminder of how much unsolved surface area exists around agent trust and data handling right now, and how early-stage a one-person tool is relative to where the rest of the market is investing.

There's no pricing to critique yet, which is consistent with everything else here: a free, week-old product from a solo founder, with no funding, no team page, and no published business model. That's not disqualifying on its own — plenty of good security tools start this way — but a vault holding SSNs and passport numbers is a different risk category than a to-do list app, and a sustainable business model (or a clear statement that this stays free and open) is a reasonable thing to want to see before storing your most sensitive data in it.

For someone who already hands agents real tasks — booking flights, filling checkout forms — trying Rivault costs nothing but the ten minutes of setup, and the underlying idea addresses a real, growing friction point. The honest caution is proportional to what's being stored: test it with lower-stakes items first, and treat the founder's own admission that the harder problem remains unsolved as the single most useful piece of information in this entire review.

AI Agents Reviewed Aug 2026

Final Verdict

ToolRadar Performance Score
5.8 / 10

Rivault's core idea — a zero-knowledge vault that lets AI agents request exactly the sensitive data they need, gated behind Face ID, instead of you retyping a passport number into a chat window — is a genuinely sensible response to a real and growing problem. The cryptographic design is sound and unremarkable in the best sense: it follows patterns that already work. What holds this back from a stronger score is entirely about timing and trust: one week old, one founder, zero independent reviews, no security audit, and a launch-day critique about the harder half of the problem that the founder didn't push back on. Worth testing with low-stakes data if you're already deep into agent workflows; worth waiting on for anything you'd genuinely lose sleep over losing.

Security Design: 7.5/10 · Convenience: 7.8/10 · Proven Track Record: 1.8/10

❓ Frequently Asked Questions

Rivault uses client-side, zero-knowledge encryption, meaning it's designed so the company's servers only ever see ciphertext. That's a sound design pattern, but Rivault launched publicly only a week ago, is built by a single founder, and has no published independent security audit yet, so treat that design as promising rather than independently proven for now.
Rivault is currently free, with no paid tiers published as of this review.
The company states it connects to OpenClaw, Claude, ChatGPT, or any AI agent through an API key or MCP, with a one-click install and no code required.
Securely storing the data is the more solved half of the problem. The harder, less-addressed half is what happens after an agent is granted access to an item — whether it retains that data longer than necessary, and whether a manipulated agent could be tricked into requesting or misusing it. A launch-day commenter raised exactly this concern, and it remains an open question.

Tired of retyping your passport number into every AI agent chat?

Rivault is free to try today — just go in with lower-stakes data first, given how new and unaudited the product still is.

🔑 Related Keywords

Rivault review AI agent data vault zero-knowledge vault AI passkey AI agent security computer-use agent data privacy MCP data vault AI agent PII security Rivault vs 1Password
Share this review
MS
Written by
Mahmoud Salamoun
Independent AI tools reviewer based in the Middle East. I test and rate AI tools so you don't have to — no sponsorships, no bias, just honest analysis.
Rate this review
(-/5)

Comments