Security

We describe implemented controls only. No system is completely secure; Vorentus does not claim zero risk and does not currently hold formal security certifications.

Implemented controls

  • Encryption in transit (TLS) and at rest in the managed database.
  • Email and password or Google authentication, with sessions managed by the identity provider.
  • Per-organisation access control enforced in the database (Row Level Security).
  • Least privilege for application and service credentials.
  • Backups managed by the database infrastructure.
  • Append-only run and observation records, which prevents retroactive changes to results.
  • Separation between development and production environments.
  • Provider review before activation.

Incidents

An internal process covers identification, containment, assessment, documentation and communication of incidents, including notification to the supervisory authority and to data subjects where legally required.

security@indicare.ai