Tenant isolation
Every API request establishes tenant context inside the database transaction. Row-level security and runtime grants provide a second, fail-closed boundary.
Trust center / precise claims
Invarent is designed so security, financial integrity, recovery, and operational evidence can be inspected. Formal certifications and professional conclusions are claimed only when an authorized independent party has issued them.
Production controls are implemented and testable. Invarent does not currently present this page as a SOC 2 report, audit opinion, DCAA approval, tax conclusion, or substitute for independent assessment.
Technical assurance record
Every API request establishes tenant context inside the database transaction. Row-level security and runtime grants provide a second, fail-closed boundary.
Balanced posting, closed-period protection, append-only audit evidence, content-bound approval, immutable source hashes, and atomic idempotency are database-enforced.
Scoped API keys and OAuth clients support hashing, rotation, revocation, expiry, usage tracking, and tenant attribution without storing reusable plaintext secrets.
Webhook destinations are constrained against private networks, revalidated at dispatch, signed, retried, dead-lettered, and replayed through an audited command.
Managed restore drills compare tenant-scoped integrity manifests for journals, trial-balance rows, audit chain state, and source hashes before service is accepted.
Metrics, black-box probes, alert rules, dashboards, structured logs, workflow state, restart counts, and rollback verification are included in the production operating model.
Shared responsibility
| Responsibility | Invarent | Customer or qualified reviewer |
|---|---|---|
| Platform security | Service configuration, tenant boundary, credentials, code, dependencies, backups, monitoring, and incident procedures | User lifecycle, source-system security, endpoint security, approved integrations, and timely access review |
| Accounting policy | Versioning, enforcement, evidence, calculation, approval workflow, and reproducibility | Entity-specific policy selection, estimates, material judgments, close approval, and professional conclusions |
| GovCon readiness | Cost, time, rate, contract, funding, billing, and evidence control surfaces | Actual procedures and operation, contract interpretation, system assessment, and government determination |
| Independent assurance | System descriptions, test evidence, remediation, and auditor access under controlled scope | Qualified independent testing and issuance of any formal report or certification |
A controlled starting point
Use the public contract and trust boundary to evaluate what Invarent enforces, what evidence it preserves, and which conclusions remain with an independent authority.