Trust · Scope and limitations visible

Controls are part of the solution—not a document added before procurement.

We design identity, data boundaries, human authority, approved tools, evaluation, monitoring, incident response, rollback, evidence, and operating ownership into the workflow from the beginning.

SOC 2 Type 2 badge, monitored by Oneleet

Current public status

SOC 2 Type II

examination completed

Scope statement

Report issued May 18, 2026 by ConstellationGRC CPA P.C. with an unqualified opinion; review period January 25–April 25, 2026.

Last public-claims review: 2026-07-26. Current diligence materials are provided through the appropriate review process.

The report defines the examined entity, system, criteria, and period. This does not establish that every product, trial, partner, or client configuration is within that boundary. Confirm the relevant scope during diligence.

Minimum trust conditions for every governed workflow.

01
Data minimization

Use only the data required for the approved workflow; keep production data out of the public fit experience.

02
Tenant and access boundaries

Least privilege, scoped identities, explicit tool access, environment separation, and client-approved connection paths.

03
Human authority

Consequential decisions and high-impact actions remain assigned to authorized people with visible approval and escalation.

04
Evaluation before activation

Representative cases, failure modes, deterministic checks, model review where used, and acceptance sign-off.

05
Operate and recover

Monitoring, exception handling, incident ownership, rollback, versioned change, and runbooks.

06
Honest evidence

Sources, conflicts, assumptions, projected versus observed value, and limitations stay attached.

Model and platform choice follows the institution’s approved boundary.

We disclose the proposed provider, data flow, purpose, retention assumptions, tool permissions, human review, and evaluation plan before activation. A named partner or platform on this website is not permission to send regulated, confidential, or cardholder data to that provider.

AI can propose, organize, extract, or draft within an agreed scope. Authorized people review consequential decisions and approve activation. An AI suggestion is not an approved lending decision, payment, or compliance sign-off. Underlying model providers and fallback routes belong in the same data review as the primary service.

Start with a safe description.

For a security concern, email [email protected] with the affected public URL and a brief description. Do not include credentials, member records, or sensitive attachments. Ask for an appropriate channel before sharing further evidence. Do not access other users’ data or disrupt the service.

This contact route does not authorize security testing or establish a bug bounty or round-the-clock response commitment. Client-specific incident reporting and support expectations belong in the agreement.

Contact Innorve about a security concern

Security diligence

Have a workflow and a control question? Bring both.

The public fit experience requires no credentials, production data, account numbers, member records, or confidential documents. Deeper diligence begins only through an approved channel.

Bring us one problem