Skip to content

Trust center / precise claims

Evidence for the controls we operate. Clear boundaries around the claims we do not.

Invarent is designed so security, financial integrity, recovery, and operational evidence can be inspected. Formal certifications and professional conclusions are claimed only when an authorized independent party has issued them.

Current assurance

Production controls are implemented and testable. Invarent does not currently present this page as a SOC 2 report, audit opinion, DCAA approval, tax conclusion, or substitute for independent assessment.

Technical assurance record

Controls that keep the trusted path narrow.

EVIDENCE / 01

Tenant isolation

Every API request establishes tenant context inside the database transaction. Row-level security and runtime grants provide a second, fail-closed boundary.

EVIDENCE / 02

Financial integrity

Balanced posting, closed-period protection, append-only audit evidence, content-bound approval, immutable source hashes, and atomic idempotency are database-enforced.

EVIDENCE / 03

Credential control

Scoped API keys and OAuth clients support hashing, rotation, revocation, expiry, usage tracking, and tenant attribution without storing reusable plaintext secrets.

EVIDENCE / 04

Delivery control

Webhook destinations are constrained against private networks, revalidated at dispatch, signed, retried, dead-lettered, and replayed through an audited command.

EVIDENCE / 05

Recovery evidence

Managed restore drills compare tenant-scoped integrity manifests for journals, trial-balance rows, audit chain state, and source hashes before service is accepted.

EVIDENCE / 06

Operational visibility

Metrics, black-box probes, alert rules, dashboards, structured logs, workflow state, restart counts, and rollback verification are included in the production operating model.

Shared responsibility

The platform can prove its controls. Customers must still operate theirs.

ResponsibilityInvarentCustomer or qualified reviewer
Platform securityService configuration, tenant boundary, credentials, code, dependencies, backups, monitoring, and incident proceduresUser lifecycle, source-system security, endpoint security, approved integrations, and timely access review
Accounting policyVersioning, enforcement, evidence, calculation, approval workflow, and reproducibilityEntity-specific policy selection, estimates, material judgments, close approval, and professional conclusions
GovCon readinessCost, time, rate, contract, funding, billing, and evidence control surfacesActual procedures and operation, contract interpretation, system assessment, and government determination
Independent assuranceSystem descriptions, test evidence, remediation, and auditor access under controlled scopeQualified independent testing and issuance of any formal report or certification

A controlled starting point

Make every assurance claim inspectable.

Use the public contract and trust boundary to evaluate what Invarent enforces, what evidence it preserves, and which conclusions remain with an independent authority.