Security and Compliance Posture
Use this article when completing a security review, and request current evidence rather than relying on marketing language.
Posture Statement
Cendryva includes security and governance controls designed to support organizational security and compliance requirements. Certification, audit, and regulatory status must be confirmed through current documentation provided by Cendryva.
Four Distinct Categories
Security questionnaires often blur these. Documentation keeps them separate:
- Implemented technical controls
- Controls present in the product today, such as role-based access, organizational scoping, and audit records of sensitive administrative actions.
- Internal readiness work
- Internal policy, process, and control work. Readiness is not an audit and not a certification.
- External audit engagement
- An engagement with an external auditor. An engagement is not a completed report.
- Completed certification or attestation
- A finished report or certificate, evidenced by a document with a scope and a date.
Important: Claims Require Approved Evidence
This documentation does not publish claims such as audit engagements in progress, certifications in progress, or regulatory compliance, unless the responsible compliance owner has supplied current documentary evidence and approved the exact wording.
How to Get What You Need
Contact Cendryva for the current security package, deployment scope, data-processing terms, and applicable compliance evidence.
For healthcare providers specifically, note that the Epic and Cerner connectors are Restricted pending healthcare-data and BAA compliance review — see the Supported Connector Catalog.