Trust Center
Approach
Confidentiality in Arrivena is enforced by the database, on every request. Access checks, consent gates, and audit logging run in the application and database layers themselves: mechanisms the system carries out on its own, not policy asked of a staff member. This page lists those mechanisms as they run today, and the engineering roadmap that extends them.
Controls that exist today
Each row below is a mechanism in the running system, not a stated intention.
| Control | Status |
|---|---|
| Consent- and partnership-gated cross-organization access, evaluated at the time of each request rather than cached | Live |
| Consent revocation takes effect immediately, in the same transaction as the revocation itself | Live |
| Uniform denial responses: an unauthorized request and a request for a record that does not exist return the same response, so neither can be used to infer whether a record exists | Live |
| Database row-level security as a second isolation layer beneath the application, independent of application logic | Live |
| Append-only event ledgers for disclosures, referrals, placements, and funding decisions | Live |
| Structured logging under a mechanical no-PHI rule: logs carry entity identifiers, not clinical or personal content | Live |
| Encrypted connections to the database | Live |
| Infrastructure defined as code, with changes reviewed before they are applied | Live |
| Independent adversarial re-verification of security-relevant changes as a standing part of the engineering process | Live |
Engineering roadmap
We publish our roadmap the same way we publish our controls: specifically.
| Control | Status |
|---|---|
| Field-level encryption at rest for sensitive attributes | Planned |
| Configurable data retention | Planned |
| Expanded audit export for customer compliance teams | Planned |
| Independent third-party penetration testing, before the product is used with regulated production data | Planned |
| SOC 2 examination | Planned |
Compliance posture
Arrivena is designed for environments governed by 42 CFR Part 2. Production infrastructure runs on HIPAA-eligible AWS services, and SedgeRidge LLC has a business associate agreement in place with AWS covering production environments. Customer-specific business associate agreements and qualified service organization agreements are executed at onboarding, per customer, and are not posted here. Every claim on this page describes a mechanism you can verify in a demonstration.
Responsible disclosure
If you believe you have found a security vulnerability in Arrivena, email security@arrivena.com with enough detail to reproduce the issue. We will acknowledge a report within one business day and will not pursue legal action against a researcher who reports a vulnerability in good faith and does not access or exfiltrate customer data beyond what is necessary to demonstrate the issue. Reports are handled directly by the engineering team; there is no paid bounty program.
Security questionnaires
If your organization needs to complete a security review before a demonstration or a contract, send your questionnaire through Inquiries and we will complete it directly.