Security and vendor review

Agree the data boundary before transferring data.

Avarent’s default evaluation path postpones sensitive-data access until a reviewer understands the proposed flow, controls, limitations, and exit procedure.

Security review sequence

  1. 01

    Classify the evaluation

    Identify the use case, data category, environment, users, and whether synthetic data can answer the first question.

  2. 02

    Map the proposed flow

    Document source, fields, transfer, storage, access, retention, deletion, subprocessors, and export behavior.

  3. 03

    Answer diligence

    Respond to the institution’s questionnaire with evidence, owners, and honest gaps. Unverified controls are not marked complete.

  4. 04

    Approve or reduce scope

    If the control posture does not justify the requested data, keep the evaluation synthetic, reduce fields, change the workflow, or stop.

What the review packet should contain

System descriptionPurpose, users, decision role, and environment
Data-flow diagramSources, transfer, processing, storage, export, and deletion
Field inventoryRequired, optional, prohibited, and derived fields
Access modelRoles, privileges, review, and revocation
Incident contactsCustomer and Avarent escalation owners
Exit procedureExport, deletion, access revocation, and confirmation

Claims boundary

Avarent does not currently claim SOC 2 certification, regulatory approval, or immunity from security incidents. Specific architecture and control evidence should be evaluated in the context of the requested pilot scope.

Report a security concern

Email security@avarent.app with “Security report” in the subject. Do not include live applicant data or credentials in the first message.