VendrNova

Evaluate security and compliance through clear status and scope

VendrNova presents certification, data-practice, and audit status as three different forms of assurance. Additional security and compliance information is available to qualified evaluators through the approved review process and, where appropriate, under confidentiality.

Certified delivery operations

ISO 27001-certified delivery operations

Data practices

GDPR-compliant data practices

Audit underway

SOC 2 Type II audit underway

Trust architecture

A diligence path built around scope and ownership.

Public statements stay exact. Architecture detail follows the approved review process.

Identity and access

Configured roles, permissions, approval policy, review context, and supported SSO architecture.

Platform safeguards

Data protection, Platform protection, logging, continuity, incident response, and security testing at public-safe scope.

Governance and traceability

Configured approvals, escalations, exceptions, access, SLA, and decision records.

Human-controlled AI

Nova recommendations and rationale remain subject to authorized human review and action.

ERP and integrations

System ownership, objects, cadence, mappings, monitoring, exceptions, and connectivity are customer-specific.

Privacy and rights

Rights and processor questions move through the approved security and privacy review path.

Review the complete public trust narrative

Identity and access

Role-based access controls can be configured to support agreed responsibilities and approval policies. Enterprise single sign-on can be configured where supported by the agreed identity architecture.

Data, platform, and operational controls

Security architecture details are shared through the approved review process. Public control wording must remain limited to the validated scope for encryption, logging and monitoring, continuity, incident response, tenant separation, secrets and keys, network protection, and testing.

Governance and traceability

VendrNova records in-scope workflow decisions and changes to support traceability and review. The Platform supports configured approval, escalation, access, SLA, exception, and audit-trail capabilities.

ERP and integration security

Integration design defines system ownership, object scope, cadence, mappings, exception handling, monitoring, notifications, and any private-connectivity requirement. Do not assume one network pattern for every customer.

Human-governed AI

Nova AI recommendations and rationale remain subject to human review and decision controls. Public use cases show the input, evidence, recommendation, authorized human action, escalation path, and audit context.

Private security review

Qualified evaluators can request additional security and compliance information through the approved review process. Materials are shared according to scope, availability, confidentiality, and the needs of the evaluation.

Use the exact Contact form contract. Do not create a separate security form.

Private diligence

Request scoped security and privacy information.

Materials are shared according to scope, availability, confidentiality, and the needs of the evaluation.

Contact security and privacy

Diligence questions

Status and next steps, stated directly.

What does “ISO 27001-certified delivery operations” mean?

It is the exact approved public wording. Additional scope information is handled through private due diligence.

What is VendrNova’s current SOC 2 Type II status?

The exact current statement is “SOC 2 Type II audit underway.”

Can security reviewers request more information?

Yes. Qualified evaluators can use the approved private review path.

Where are approval and exception controls explained?

The Governance and Compliance route explains authority, evidence, exception, boundary, and trace controls.

Try the non-transmitting data-rights demonstration

This form demonstrates accessible validation without transmitting information.

Demonstration form

Data rights request

Demonstration only — no information is submitted.

Do not include identification documents in this demonstration.

Security and governance

Start a diligence conversation with status, scope, and ownership clear.

Bring the security, privacy, AI-governance, integration, and evidence questions your review must resolve.

Start a diligence conversationReview governance controls