Trust Center

Approach

Confidentiality in Arrivena is enforced by the database, on every request. Access checks, consent gates, and audit logging run in the application and database layers themselves: mechanisms the system carries out on its own, not policy asked of a staff member. This page lists those mechanisms as they run today, and the engineering roadmap that extends them.

Controls that exist today

Each row below is a mechanism in the running system, not a stated intention.

Controls that exist today
Control Status
Consent- and partnership-gated cross-organization access, evaluated at the time of each request rather than cached Live
Consent revocation takes effect immediately, in the same transaction as the revocation itself Live
Uniform denial responses: an unauthorized request and a request for a record that does not exist return the same response, so neither can be used to infer whether a record exists Live
Database row-level security as a second isolation layer beneath the application, independent of application logic Live
Append-only event ledgers for disclosures, referrals, placements, and funding decisions Live
Structured logging under a mechanical no-PHI rule: logs carry entity identifiers, not clinical or personal content Live
Encrypted connections to the database Live
Infrastructure defined as code, with changes reviewed before they are applied Live
Independent adversarial re-verification of security-relevant changes as a standing part of the engineering process Live

Engineering roadmap

We publish our roadmap the same way we publish our controls: specifically.

Engineering roadmap
Control Status
Field-level encryption at rest for sensitive attributes Planned
Configurable data retention Planned
Expanded audit export for customer compliance teams Planned
Independent third-party penetration testing, before the product is used with regulated production data Planned
SOC 2 examination Planned

Compliance posture

Arrivena is designed for environments governed by 42 CFR Part 2. Production infrastructure runs on HIPAA-eligible AWS services, and SedgeRidge LLC has a business associate agreement in place with AWS covering production environments. Customer-specific business associate agreements and qualified service organization agreements are executed at onboarding, per customer, and are not posted here. Every claim on this page describes a mechanism you can verify in a demonstration.

Responsible disclosure

If you believe you have found a security vulnerability in Arrivena, email security@arrivena.com with enough detail to reproduce the issue. We will acknowledge a report within one business day and will not pursue legal action against a researcher who reports a vulnerability in good faith and does not access or exfiltrate customer data beyond what is necessary to demonstrate the issue. Reports are handled directly by the engineering team; there is no paid bounty program.

Security questionnaires

If your organization needs to complete a security review before a demonstration or a contract, send your questionnaire through Inquiries and we will complete it directly.