VendrNova
Evaluate security and compliance through clear status and scope
VendrNova presents certification, data-practice, and audit status as three different forms of assurance. Additional security and compliance information is available to qualified evaluators through the approved review process and, where appropriate, under confidentiality.
GDPR-compliant data practices
SOC 2 Type II audit underway
Trust architecture
A diligence path built around scope and ownership.
Public statements stay exact. Architecture detail follows the approved review process.
Identity and access
Configured roles, permissions, approval policy, review context, and supported SSO architecture.
Platform safeguards
Data protection, Platform protection, logging, continuity, incident response, and security testing at public-safe scope.
Governance and traceability
Configured approvals, escalations, exceptions, access, SLA, and decision records.
Human-controlled AI
Nova recommendations and rationale remain subject to authorized human review and action.
ERP and integrations
System ownership, objects, cadence, mappings, monitoring, exceptions, and connectivity are customer-specific.
Privacy and rights
Rights and processor questions move through the approved security and privacy review path.
Review the complete public trust narrative
Identity and access
Role-based access controls can be configured to support agreed responsibilities and approval policies. Enterprise single sign-on can be configured where supported by the agreed identity architecture.
Data, platform, and operational controls
Security architecture details are shared through the approved review process. Public control wording must remain limited to the validated scope for encryption, logging and monitoring, continuity, incident response, tenant separation, secrets and keys, network protection, and testing.
Governance and traceability
VendrNova records in-scope workflow decisions and changes to support traceability and review. The Platform supports configured approval, escalation, access, SLA, exception, and audit-trail capabilities.
ERP and integration security
Integration design defines system ownership, object scope, cadence, mappings, exception handling, monitoring, notifications, and any private-connectivity requirement. Do not assume one network pattern for every customer.
Human-governed AI
Nova AI recommendations and rationale remain subject to human review and decision controls. Public use cases show the input, evidence, recommendation, authorized human action, escalation path, and audit context.
Private security review
Qualified evaluators can request additional security and compliance information through the approved review process. Materials are shared according to scope, availability, confidentiality, and the needs of the evaluation.
Use the exact Contact form contract. Do not create a separate security form.
Private diligence
Request scoped security and privacy information.
Materials are shared according to scope, availability, confidentiality, and the needs of the evaluation.
Diligence questions
Status and next steps, stated directly.
What does “ISO 27001-certified delivery operations” mean?
It is the exact approved public wording. Additional scope information is handled through private due diligence.
What is VendrNova’s current SOC 2 Type II status?
The exact current statement is “SOC 2 Type II audit underway.”
Can security reviewers request more information?
Yes. Qualified evaluators can use the approved private review path.
Where are approval and exception controls explained?
The Governance and Compliance route explains authority, evidence, exception, boundary, and trace controls.
Try the non-transmitting data-rights demonstration
This form demonstrates accessible validation without transmitting information.