Security & Trust
Security your team can sign off — the first time.
Essenvia keeps regulated products legally sellable, so the platform behind your submissions and registrations has to clear the same bar your own quality and IT reviews do. It does — and it’s attested by independent third parties, not just claimed.
Independently audited. SOC 2 Type II · penetration tested · OWASP-Top-10-for-LLM reviewed.
SOC 2 Type II
Security, Availability & Confidentiality — tested over time
Independent penetration test
Production app + cloud, OWASP & NIST methodology
OWASP Top 10 for LLM review
AI components tested as a critical pathway
Formal AI-governance program
Human-in-the-loop, documented and owned
SOC 2 Type II
Penetration tested
OWASP Top 10 for LLM
21 CFR Part 11
GDPR
HIPAA
EU MDR
Independently verified
Attestations, not assertions.
The fastest way to trust a newer vendor is to check the work of the people paid to be skeptical of it. Three independent examinations sit under everything else on this page.
SOC 2 Type II
An independent service auditor examined our controls for operating effectiveness over a period — the meaningful bar, not a one-day snapshot.
Trust criteria
Security · Availability · Confidentiality
Type
Type II (tested over time)
Result
No exceptions noted
Incidents in period
None
Penetration test
An independent security firm tested our production web app and AWS environment, then delivered findings and remediation.
Conducted
February 2026
Methodology
OWASP WSTG · NIST SP 800-115
Scope
Web app + AWS infrastructure
Cadence
Annual + quarterly scans
AI & LLM security review
The same engagement evaluated our AI against the OWASP Top 10 for LLM (2025) — the AI treated as a critical pathway, not a black box.
Prompt injection
Input fuzzing + output filtering
Data disclosure
Model data & weights isolated
Excessive agency
Least-privilege AI accounts
Abuse & DoS
WAF + API rate limiting
Defense in depth
Secured at every layer — network, application, data.
No single control is the only thing between an attacker and your data. Essenvia runs on a hardened, isolated AWS architecture with controls enforced from the network edge to the data store.
Access & identity
Role-based access on least privilege — scoped to what each role needs
SSO and multi-factor authentication at a single controlled entry point
Authorization enforced at the application layer, never trusted to the front end
Network isolation
Private VPC — components aren’t directly exposed to the internet
Service-to-service traffic over secured internal pathways only
AWS WAF & API Gateway enforce rate limits, request validation and timeouts
Encryption & secrets
Encrypted at rest and in transit with centrally managed keys
Secrets held in a dedicated secrets manager — never in code
Ingested content integrity-checked before it’s indexed
Monitoring & response
Continuous threat detection across the environment
Centralized logging of app, access and infrastructure activity
Quarterly vulnerability scans and a documented incident-response plan
AI you can govern
The AI-governance evidence most vendors can’t show you.
Essenvia is AI-native in a domain where a wrong output can put market access at risk. So our AI runs under a formal, documented governance program — owned, reviewed annually, and mapped to the regulations you answer to.
Human in the loop by design — AI assists, people decide; low-confidence outputs are flagged for expert review
Transparent & explainable — AI-generated content is labeled, with explainability and documented model limitations
Your data isn’t the training set — sensitive data is anonymized; model data and weights are isolated
Bias tested across jurisdictions — fairness metrics evaluated alongside accuracy, not after it
Vetted foundation models — providers assessed and covered by signed Data Processing Agreements
AI Governance & Ethics Policy
A formal, owned policy — with a scheduled annual review — governing every AI capability in the platform.
Human oversight
Required at every stage
Explainability
Documented
Bias & fairness
Monitored
Aligned to
21 CFR Part 11 · GDPR · HIPAA · EU MDR
Data protection & privacy
Your regulatory records, handled like the sensitive assets they are.
In our custody
Encrypted at rest and in transit
Confidentiality & NDAs with staff, contractors and third parties
Your data used only for the purposes in your agreement
Defined data-retention and secure-disposal practices
With our subprocessors
Cloud, AI and service providers covered by signed DPAs
Providers assessed for enterprise-grade data isolation
Personal data anonymized or pseudonymized before AI processing
Support for data access, correction and deletion requests
SOC 2 Type II is an independent attestation held by Essenvia. 21 CFR Part 11, GDPR, HIPAA and EU MDR describe the regulatory regimes the platform is designed to support; certification status for any specific standard is confirmed on request.
Availability & resilience
Regulatory deadlines don’t move — so neither do we.
Our business-continuity and disaster-recovery program is built around tested recovery objectives, so an outage never becomes a missed submission.
System
Recovery time (RTO)
Recovery point (RPO)
Production application
4 hours
15 minutes
Database
2 hours
15 minutes
Internal tools
8 hours
1 hour
Communications
4 hours
1 hour
Resilient backups
Automated, encrypted backups replicated across regions, with recovery monitored for successful replication and disaster-recovery tests — including backup restoration — run on a defined schedule.
Continuous availability
A documented BC/DR plan with defined roles and objectives, production availability monitoring, and the underlying SLAs of our AWS cloud infrastructure.
Validation, lifted off your team
We provide the IQ / OQ / PQ packages — protocols, scripts and traceability — so qualifying Essenvia isn’t a burden you build from scratch.
Installation Qualification
Provided
Operational Qualification
Provided
Performance Qualification
Provided
Change control
Formal SOP
Validation & quality management
Built to be validated — and audited.
Medtech teams don’t just buy software; they have to validate it. Essenvia is documented for exactly that, with a quality system aligned to 21 CFR Part 11 expectations.
A Quality Manual and controlled SOPs govern how the platform is built, changed and supported
Formal change control and customer-issue-resolution processes, with sign-off gates
Comprehensive audit trails and versioning — so the system of record behind your product holds up to the same scrutiny your product does
SOC 2
Type II, independently audited
Zero
exceptions noted in the audit period
Annual
penetration test + quarterly scans
15 min
recovery point objective on core data
Straight answers
What security reviewers ask us.
Do you train your AI models on our data?
No. Sensitive data is anonymized or pseudonymized before any model use, and model data and weights are isolated at the infrastructure layer — a control verified in our independent LLM-security review.
Is your data encrypted?
Yes — at rest and in transit, using centrally managed keys, with secrets held in a dedicated secrets-management service rather than in code.
How often are you penetration tested?
An independent security firm performs an annual penetration test — most recently February 2026, using OWASP and NIST methodology — supported by quarterly vulnerability scans and source-code scanning.
Which frameworks do you support?
We hold a SOC 2 Type II attestation covering Security, Availability and Confidentiality, and the platform is designed to support 21 CFR Part 11, GDPR, HIPAA and EU MDR. We’ll confirm status for any specific standard on request.
Can we see the underlying documentation?
Yes. Under NDA we’ll share the SOC 2 report, penetration-test attestation, AI-governance policy, DPAs, BC/DR plan and validation packages, and walk your team through them.
What happens in an outage?
Our BC/DR plan defines tested recovery objectives — core application within 4 hours and a 15-minute recovery point — backed by encrypted, cross-region backups and regular restoration tests.
Request our security package.
Doing a vendor security review? We’ll share the documentation under NDA and walk your security, IT and quality teams through it — so you can verify, not just take our word for it.
SOC 2 Type II report
Penetration-test attestation
AI & LLM risk-coverage statement
AI Governance & Ethics Policy
Information Security Policy
BC/DR plan
Data Processing Agreements
IQ/OQ/PQ & QMS documentation
