Everything a vendor-security review needs — subprocessors, compliance mapping, and signed documentation — available on request, watermarked to your organization.
Our security posture: Diliventa runs entirely on infrastructure that holds independent SOC 2 and ISO certifications, governed by a Unified Control Framework mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, and GDPR. An independent SOC 2 Type II examination of Diliventa itself is on our roadmap — see Compliance Posture below for current status.
Diliventa's own security posture and control mapping, provided directly since no independent audit report exists yet.
CEO/CISO-signed control-by-control attestation mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, and GDPR.
Governance, architecture, data protection, access control, AI handling, subprocessors, and compliance posture in one document.
Every subprocessor, what data they touch, and their independent certifications. Where a subprocessor publishes its own trust portal, we link directly so you can request their report without waiting on us.
| Subprocessor | Function | Independent assurance |
|---|---|---|
| Cloudflare | Edge compute, object storage, DB pooling, WAF/DDoS | SOC 2 Type II · ISO 27001 |
| Neon | PostgreSQL data tier | SOC 2 Type II |
| WorkOS | Identity and authentication | SOC 2 Type II |
| Stripe | Billing and subscription management | SOC 2 · PCI DSS Level 1 |
| Anthropic | AI analysis (cloud mode) | SOC 2 Type II · executed DPA |
| Cloudmersive | Malware/virus scanning and OCR of uploaded evidence | Not independently verified — ask us for their current status |
| Resend | Transactional email delivery | SOC 2 Type II |
| Sentry | Error monitoring and performance telemetry | SOC 2 Type II · ISO 27001 |
Detailed inherited-controls statement covering every subprocessor above, what data they touch, and how their certifications flow through to Diliventa's own posture.
What our AI analysis features process, how cloud-mode data is handled, and the human-oversight controls in place.
What the AI processes, cloud-mode data handling, human oversight, and the standards it's mapped to.
Data Processing Agreements, mutual NDAs, and standard contractual terms for your legal and procurement review.
Standard mutual non-disclosure agreement to put in place before deeper technical or commercial discussions, if your process requires one ahead of the confidential documents above.
Download template →Standard DPA covering data protection terms, subprocessor flow-down, and cross-border transfer safeguards.
Email to request →Diliventa's full internal security policy library — access control, incident response, data retention, encryption, vendor risk, AI governance, and more — for reviewers who need policy-level detail.
37 controlled policies plus the Unified Control Framework and Master Document Register, mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, and GDPR.
| Item | Status |
|---|---|
| Security program mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, GDPR | In place |
| Infrastructure subprocessors independently certified | In place — verifiable |
| Independent SOC 2 Type II examination of Diliventa | Planned / roadmap |
| Independent penetration test | Planned / roadmap |
| Data residency | United States |
| DPA / BAA availability | Available on request |
Need a completed security questionnaire (HECVAT, SIG Lite, CAIQ)? Email security@diliventa.io and we'll get it to you.
Completed questionnaires, mutual NDAs, or anything not listed above — just ask.