Security & Trust

Security your team can sign off — the first time.

Essenvia keeps regulated products legally sellable, so the platform behind your submissions and registrations has to clear the same bar your own quality and IT reviews do. It does — and it’s attested by independent third parties, not just claimed.

Independently audited. SOC 2 Type II · penetration tested · OWASP-Top-10-for-LLM reviewed.

SOC 2 Type II

Security, Availability & Confidentiality — tested over time

Independent penetration test

Production app + cloud, OWASP & NIST methodology

OWASP Top 10 for LLM review

AI components tested as a critical pathway

Formal AI-governance program

Human-in-the-loop, documented and owned

SOC 2 Type II

Penetration tested

OWASP Top 10 for LLM

21 CFR Part 11

GDPR

HIPAA

EU MDR

Independently verified

Attestations, not assertions.

The fastest way to trust a newer vendor is to check the work of the people paid to be skeptical of it. Three independent examinations sit under everything else on this page.

SOC 2 Type II

An independent service auditor examined our controls for operating effectiveness over a period — the meaningful bar, not a one-day snapshot.

Trust criteria

Security · Availability · Confidentiality

Type

Type II (tested over time)

Result

No exceptions noted

Incidents in period

None

Penetration test

An independent security firm tested our production web app and AWS environment, then delivered findings and remediation.

Conducted

February 2026

Methodology

OWASP WSTG · NIST SP 800-115

Scope

Web app + AWS infrastructure

Cadence

Annual + quarterly scans

AI & LLM security review

The same engagement evaluated our AI against the OWASP Top 10 for LLM (2025) — the AI treated as a critical pathway, not a black box.

Prompt injection

Input fuzzing + output filtering

Data disclosure

Model data & weights isolated

Excessive agency

Least-privilege AI accounts

Abuse & DoS

WAF + API rate limiting

Defense in depth

Secured at every layer — network, application, data.

No single control is the only thing between an attacker and your data. Essenvia runs on a hardened, isolated AWS architecture with controls enforced from the network edge to the data store.

Access & identity

Role-based access on least privilege — scoped to what each role needs

SSO and multi-factor authentication at a single controlled entry point

Authorization enforced at the application layer, never trusted to the front end

Network isolation

Private VPC — components aren’t directly exposed to the internet

Service-to-service traffic over secured internal pathways only

AWS WAF & API Gateway enforce rate limits, request validation and timeouts

Encryption & secrets

Encrypted at rest and in transit with centrally managed keys

Secrets held in a dedicated secrets manager — never in code

Ingested content integrity-checked before it’s indexed

Monitoring & response

Continuous threat detection across the environment

Centralized logging of app, access and infrastructure activity

Quarterly vulnerability scans and a documented incident-response plan

AI you can govern

The AI-governance evidence most vendors can’t show you.

Essenvia is AI-native in a domain where a wrong output can put market access at risk. So our AI runs under a formal, documented governance program — owned, reviewed annually, and mapped to the regulations you answer to.

Human in the loop by design — AI assists, people decide; low-confidence outputs are flagged for expert review

Transparent & explainable — AI-generated content is labeled, with explainability and documented model limitations

Your data isn’t the training set — sensitive data is anonymized; model data and weights are isolated

Bias tested across jurisdictions — fairness metrics evaluated alongside accuracy, not after it

Vetted foundation models — providers assessed and covered by signed Data Processing Agreements

AI Governance & Ethics Policy

A formal, owned policy — with a scheduled annual review — governing every AI capability in the platform.

Human oversight

Required at every stage

Explainability

Documented

Bias & fairness

Monitored

Aligned to

21 CFR Part 11 · GDPR · HIPAA · EU MDR

Data protection & privacy

Your regulatory records, handled like the sensitive assets they are.

In our custody

Encrypted at rest and in transit

Confidentiality & NDAs with staff, contractors and third parties

Your data used only for the purposes in your agreement

Defined data-retention and secure-disposal practices

With our subprocessors

Cloud, AI and service providers covered by signed DPAs

Providers assessed for enterprise-grade data isolation

Personal data anonymized or pseudonymized before AI processing

Support for data access, correction and deletion requests

SOC 2 Type II is an independent attestation held by Essenvia. 21 CFR Part 11, GDPR, HIPAA and EU MDR describe the regulatory regimes the platform is designed to support; certification status for any specific standard is confirmed on request.

Availability & resilience

Regulatory deadlines don’t move — so neither do we.

Our business-continuity and disaster-recovery program is built around tested recovery objectives, so an outage never becomes a missed submission.

System

Recovery time (RTO)

Recovery point (RPO)

Production application

4 hours

15 minutes

Database

2 hours

15 minutes

Internal tools

8 hours

1 hour

Communications

4 hours

1 hour

Resilient backups

Automated, encrypted backups replicated across regions, with recovery monitored for successful replication and disaster-recovery tests — including backup restoration — run on a defined schedule.

Continuous availability

A documented BC/DR plan with defined roles and objectives, production availability monitoring, and the underlying SLAs of our AWS cloud infrastructure.

Validation, lifted off your team

We provide the IQ / OQ / PQ packages — protocols, scripts and traceability — so qualifying Essenvia isn’t a burden you build from scratch.

Installation Qualification

Provided

Operational Qualification

Provided

Performance Qualification

Provided

Change control

Formal SOP

Validation & quality management

Built to be validated — and audited.

Medtech teams don’t just buy software; they have to validate it. Essenvia is documented for exactly that, with a quality system aligned to 21 CFR Part 11 expectations.

A Quality Manual and controlled SOPs govern how the platform is built, changed and supported

Formal change control and customer-issue-resolution processes, with sign-off gates

Comprehensive audit trails and versioning — so the system of record behind your product holds up to the same scrutiny your product does

SOC 2

Type II, independently audited

Zero

exceptions noted in the audit period

Annual

penetration test + quarterly scans

15 min

recovery point objective on core data

Straight answers

What security reviewers ask us.

Do you train your AI models on our data?

No. Sensitive data is anonymized or pseudonymized before any model use, and model data and weights are isolated at the infrastructure layer — a control verified in our independent LLM-security review.

Is your data encrypted?

Yes — at rest and in transit, using centrally managed keys, with secrets held in a dedicated secrets-management service rather than in code.

How often are you penetration tested?

An independent security firm performs an annual penetration test — most recently February 2026, using OWASP and NIST methodology — supported by quarterly vulnerability scans and source-code scanning.

Which frameworks do you support?

We hold a SOC 2 Type II attestation covering Security, Availability and Confidentiality, and the platform is designed to support 21 CFR Part 11, GDPR, HIPAA and EU MDR. We’ll confirm status for any specific standard on request.

Can we see the underlying documentation?

Yes. Under NDA we’ll share the SOC 2 report, penetration-test attestation, AI-governance policy, DPAs, BC/DR plan and validation packages, and walk your team through them.

What happens in an outage?

Our BC/DR plan defines tested recovery objectives — core application within 4 hours and a 15-minute recovery point — backed by encrypted, cross-region backups and regular restoration tests.

Request our security package.

Doing a vendor security review? We’ll share the documentation under NDA and walk your security, IT and quality teams through it — so you can verify, not just take our word for it.

SOC 2 Type II report

Penetration-test attestation

AI & LLM risk-coverage statement

AI Governance & Ethics Policy

Information Security Policy

BC/DR plan

Data Processing Agreements

IQ/OQ/PQ & QMS documentation

Learn More About the Essenvia Platform

Contact us for a Demo

Learn More About the Essenvia Platform

Contact us for a Demo

Learn More About the Essenvia Platform

Contact us for a Demo