Security

Trust Center

Everything a vendor-security review needs — subprocessors, compliance mapping, and signed documentation — available on request, watermarked to your organization.

Request a Document Ask a Question
Cloudflare SOC 2 · ISO 27001 Neon SOC 2 WorkOS SOC 2 Stripe SOC 2 · PCI DSS L1 Anthropic SOC 2 Resend SOC 2 Sentry SOC 2 · ISO 27001

These certifications belong to Diliventa's infrastructure subprocessors, shown here for transparency — see Compliance posture for Diliventa's own status. Last updated August 26, 2026 · security@diliventa.io

Our security posture: Diliventa runs entirely on infrastructure that holds independent SOC 2 and ISO certifications, governed by a Unified Control Framework mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, and GDPR. An independent SOC 2 Type II examination of Diliventa itself is on our roadmap — see Compliance Posture below for current status.

Compliance & Attestations

Diliventa's own security posture and control mapping, provided directly since no independent audit report exists yet.

Confidential — request required

Vendor Security Self-Attestation

CEO/CISO-signed control-by-control attestation mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, and GDPR.

Confidential — request required

Security & Trust Overview

Governance, architecture, data protection, access control, AI handling, subprocessors, and compliance posture in one document.

Subprocessors & Infrastructure

Every subprocessor, what data they touch, and their independent certifications. Where a subprocessor publishes its own trust portal, we link directly so you can request their report without waiting on us.

SubprocessorFunctionIndependent assurance
CloudflareEdge compute, object storage, DB pooling, WAF/DDoSSOC 2 Type II · ISO 27001
NeonPostgreSQL data tierSOC 2 Type II
WorkOSIdentity and authenticationSOC 2 Type II
StripeBilling and subscription managementSOC 2 · PCI DSS Level 1
AnthropicAI analysis (cloud mode)SOC 2 Type II · executed DPA
CloudmersiveMalware/virus scanning and OCR of uploaded evidenceNot independently verified — ask us for their current status
ResendTransactional email deliverySOC 2 Type II
SentryError monitoring and performance telemetrySOC 2 Type II · ISO 27001
Confidential — request required

Subprocessor Assurance Statement

Detailed inherited-controls statement covering every subprocessor above, what data they touch, and how their certifications flow through to Diliventa's own posture.

AI & Data Handling

What our AI analysis features process, how cloud-mode data is handled, and the human-oversight controls in place.

Confidential — request required

AI Data Handling & Transparency Statement

What the AI processes, cloud-mode data handling, human oversight, and the standards it's mapped to.

Data Privacy & Legal Agreements

Data Processing Agreements, mutual NDAs, and standard contractual terms for your legal and procurement review.

Public

Mutual NDA Template

Standard mutual non-disclosure agreement to put in place before deeper technical or commercial discussions, if your process requires one ahead of the confidential documents above.

Download template →
Available on request

Data Processing Agreement (DPA)

Standard DPA covering data protection terms, subprocessor flow-down, and cross-border transfer safeguards.

Email to request →

Security Policies

Diliventa's full internal security policy library — access control, incident response, data retention, encryption, vendor risk, AI governance, and more — for reviewers who need policy-level detail.

Confidential — request required

Security Policy Package

37 controlled policies plus the Unified Control Framework and Master Document Register, mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, and GDPR.

Compliance Posture

ItemStatus
Security program mapped to SOC 2, NIST CSF 2.0, ISO 27001, CIS v8.1, HIPAA, GDPRIn place
Infrastructure subprocessors independently certifiedIn place — verifiable
Independent SOC 2 Type II examination of DiliventaPlanned / roadmap
Independent penetration testPlanned / roadmap
Data residencyUnited States
DPA / BAA availabilityAvailable on request

Need a completed security questionnaire (HECVAT, SIG Lite, CAIQ)? Email security@diliventa.io and we'll get it to you.

Don't see what you need?

Completed questionnaires, mutual NDAs, or anything not listed above — just ask.

Email security@diliventa.io