Trust Center · Vendor diligence

Clear the vendor review
before it starts.

In regulated finance, vendor diligence kills more engagements than demos do. This page exists so your risk, security, and compliance reviewers can do their job without a single email to us — the report status, the data model, and the disclosures are all here.

Request the Diligence Pack Start with SOC 2
Independent examination

SOC 2 Type II — unqualified opinion

Innorve Inc. completed a SOC 2 Type II examination. The report was issued May 18, 2026 by ConstellationGRC CPA P.C. with an unqualified opinion, covering January 25–April 25, 2026.

Type II means the auditor tested that our controls operated effectively across the whole examination window — not a single point in time. The full report, including the auditor’s description of tests and results, is available under NDA in the Diligence Pack below.

Report typeSOC 2 Type II
OpinionUnqualified
AuditorConstellationGRC CPA P.C.
IssuedMay 18, 2026
PeriodJan 25 – Apr 25, 2026
Data-handling model

We ship answers, not your data.

Your data stays yours. Engagements run against your institution’s own data inside your environment, and what leaves is a governed answer or artifact — not a copy of your records. Our cited Knowledge Fiber is the reference we bring; your operational data is never absorbed into it.

Your environment
Your data stays put
Records, SOPs, and PII remain inside your systems.
Knowledge Fiber
Reference, applied
Our cited Knowledge Fiber informs the work — it does not ingest your data.
You keep
A governed answer
Code, maps, and records — owned by you, on your infrastructure.
Record integrity

Hash-chained, tamper-evident records

Outcome records and decision packages are hash-chained: each entry carries a cryptographic hash of the one before it, so any later edit to an earlier record breaks the chain and is detectable on review.

We say tamper-evident, not tamper-proof. Hash-chaining makes changes detectable — it does not make records physically unchangeable, and we don’t use blockchain or call anything “immutable.” The point is an auditor can verify a record hasn’t been altered since it was written.

Health-data posture

HIPAA-aligned approach

Where an engagement touches health-related information — for example, certain hardship, disability, or benefits workflows — we work to a HIPAA-aligned approach: minimum-necessary handling, access controls, and a Business Associate Agreement where one is warranted.

“Aligned” is deliberate wording: it describes how we design and operate, scoped to the specific engagement, rather than a blanket certification claim.

Subprocessor & AI-use disclosure

How we use AI, and who we rely on.

We disclose our material subprocessors and where AI sits in the work. AI accelerates analysis and drafting; a qualified human reviews and is accountable for every output that reaches a client. AI does not make final compliance determinations.

Anthropic

Large-language-model inference for analysis and drafting, under enterprise terms.

Databricks

Governed data and processing platform for engagement workloads.

UiPath

Automation runtime for governed production workflows.

Microsoft Azure

Cloud infrastructure and hosting for engagement environments.

The authoritative, engagement-specific subprocessor list and data-flow diagrams ship in the Diligence Pack and in your engagement’s data-processing addendum.

Reviewer checklist

What you can confirm without emailing us

A current SOC 2 Type II examination exists, with an unqualified opinion and named auditor.
Client data stays in the client environment; only governed answers and artifacts leave.
Outcome records are hash-chained and tamper-evident, described honestly.
A HIPAA-aligned approach is available where an engagement warrants it.
Material subprocessors and the role of AI are disclosed.
A full Diligence Pack (report, DPA, subprocessor list) is available under NDA.
The Security & Diligence Pack

One request. Everything your review needs.

Tell us where to send it and we’ll grant access to the full pack for your review team. Sensitive documents (the SOC 2 report itself, the DPA, and the authoritative subprocessor list) are shared under NDA.

  • SOC 2 Type II report (under NDA)
  • Data-processing addendum & data-flow diagram
  • Subprocessor list & AI-use statement
  • Security overview & standard questionnaire responses

Access is granted by a person, not automatically. Expect a reply within one business day.

Request access

We use your details only to grant and manage access to the pack. See our privacy note.

Trust

Diligence cleared? Bring us the workflow.

The trust ladder ends where the work begins. When your review is done, the fastest next step is one stuck workflow.

InnorveForward-deployed engineering for regulated financial institutions
AboutProofContactPrivacy© 2026 Innorve