Security & compliance
DRYVN is built for operators who need controlled access, scoped credentials, tenant-aware workflows, and human-reviewed client delivery.
Compliance posture
SOC 2 Type II (Security · Confidentiality · Privacy) — independent report by Advisor One, CPA, available under NDA.
HITRUST CSF-certified HIPAA program; BAA available for PHI engagements.
ISO/IEC 27001 & 27701 — certification complete; formal certificate and documentation provided to clients on request.
Privacy / PII: EU-U.S. Data Privacy Framework participant; ISO/IEC 27018 cloud-PII handling.
Transparency: Every privileged action is audit-logged; continuous instrumentation.
Client data handling
DRYVN uses centralized secret management, service-scoped credential delivery, tenant-aware access patterns, and audit trails for sensitive operations. Workers receive only the credentials relevant to the assigned service and lane; access expansion or exceptions require security-team review.
Healthcare / PHI
PHI engagements require an approved PHI scope and BAA. Do not submit PHI to DRYVN outside an expressly approved PHI engagement.
Report access
SOC 2 report, HITRUST materials, and BAA are available to qualified clients under NDA / on request.
No badges, certificate IDs, or report excerpts are shown here.
SOC 2 report, HITRUST materials, BAA, and supporting review detail are handled under NDA/on request for qualified clients.