Security and vendor review
Agree the data boundary before transferring data.
Avarent’s default evaluation path postpones sensitive-data access until a reviewer understands the proposed flow, controls, limitations, and exit procedure.
Security review sequence
- 01
Classify the evaluation
Identify the use case, data category, environment, users, and whether synthetic data can answer the first question.
- 02
Map the proposed flow
Document source, fields, transfer, storage, access, retention, deletion, subprocessors, and export behavior.
- 03
Answer diligence
Respond to the institution’s questionnaire with evidence, owners, and honest gaps. Unverified controls are not marked complete.
- 04
Approve or reduce scope
If the control posture does not justify the requested data, keep the evaluation synthetic, reduce fields, change the workflow, or stop.
What the review packet should contain
Claims boundary
Avarent does not currently claim SOC 2 certification, regulatory approval, or immunity from security incidents. Specific architecture and control evidence should be evaluated in the context of the requested pilot scope.
Report a security concern
Email security@avarent.app with “Security report” in the subject. Do not include live applicant data or credentials in the first message.