NEWS
Verax AI Risk Assessment is live. See what's exposed
Riverside.fm
Riverside.fm
 
Risk Overview
Moderate Risk
4.3
/10
Speech to Text
·
Audio Generation
·
Audio Editing
·
Top Risks

Mandatory arbitration clause plus class action waiver—highest legal risk in this batch; outdated privacy policy (2022); guest recording creates third-party data subjects who may not have reviewed Riverside's terms; Israeli jurisdiction nuances; recording of audio/video sessions is inherently high-sensitivity data.

Mitigations

DPA available for business customers provides stronger data protection guarantees. SOC 2 and ISO 27001 certifications are strong security positives. Inform guests of recording and data storage practices. Use local recording mode where possible to reduce cloud exposure. Review arbitration clause before business-critical use. Request updated DPA for enterprise deployments.

Get started
Is your team using 
Riverside.fm
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Legal Terms

ToS contains mandatory binding arbitration clause: 'any dispute, claim or controversy arising out of or relating to these Terms or your use of services shall be determined by binding arbitration on an individual basis rather than in court.' Class action waiver: 'Users and Riverside waive the right to a trial by jury or to participate in a class action.' Small claims court exception applies. This is the most aggressive legal posture found in this batch—mandatory arbitration plus class action waiver is the combination that triggers highest legal risk scores.
7
/10

Data Retention

Privacy policy (dated June 22, 2022—notably outdated) does not specify retention periods clearly. Recordings are stored in user accounts until deleted. No explicit auto-deletion or post-deletion window stated in accessible policy text. The DPA (Dec 2024 version) governs business customer data processing. Guest recordings retention depends on host account settings. Recording retention is a concern for a podcast tool where third-party guests participate.
5
/10

Data Sovereignty

Israeli-founded company (Asaf Oran, Nadav Keyson); US commercial operations. Israeli entity with significant US presence. Israel has GDPR adequacy decision from EU. SOC 2 and ISO 27001 certified. Data likely processed on US/EU cloud infrastructure. US CLOUD Act applies to US operations. Israeli intelligence collection laws (Unit 8200 alumni-founded companies sometimes draw scrutiny) create some sovereign risk perception, though Israel has adequate data protection. No China nexus.
5
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.