Security and Compliance Posture

Use this article when completing a security review, and request current evidence rather than relying on marketing language.

Availability: Core4 min readLast reviewed September 3, 2026

Posture Statement

Cendryva includes security and governance controls designed to support organizational security and compliance requirements. Certification, audit, and regulatory status must be confirmed through current documentation provided by Cendryva.

Four Distinct Categories

Security questionnaires often blur these. Documentation keeps them separate:

Implemented technical controls
Controls present in the product today, such as role-based access, organizational scoping, and audit records of sensitive administrative actions.
Internal readiness work
Internal policy, process, and control work. Readiness is not an audit and not a certification.
External audit engagement
An engagement with an external auditor. An engagement is not a completed report.
Completed certification or attestation
A finished report or certificate, evidenced by a document with a scope and a date.

Important: Claims Require Approved Evidence

This documentation does not publish claims such as audit engagements in progress, certifications in progress, or regulatory compliance, unless the responsible compliance owner has supplied current documentary evidence and approved the exact wording.

How to Get What You Need

Contact Cendryva for the current security package, deployment scope, data-processing terms, and applicable compliance evidence.

For healthcare providers specifically, note that the Epic and Cerner connectors are Restricted pending healthcare-data and BAA compliance review — see the Supported Connector Catalog.