Security and Trust
The first security decision is what Varosync is allowed to receive. Public requests, commercial records and scientific evidence use different channels. Private evidence moves only after Varosync accepts the material and the governing documents identify its permitted use.
Keep restricted material out of the public request
The public configurator accepts a public description of the decision and program. Do not submit patient information, unpublished results, MNPI, data-room material, export-controlled material or information you are not authorized to disclose.
A submitted request is reviewed for fit. It is not a secure intake channel and does not create an Order.
The order room handles the purchase
The private order room may hold the Order, organization and role information, agreement status, procurement instructions, billing records, payment status and project-administration answers. It is not the scientific workspace. Research files and patient information do not belong in the order room, on a payment page, in a support request or in ordinary email.
Private evidence requires written authorization
Before private evidence moves, Varosync determines whether the proposed material can be accepted for the Order. The applicable documents identify the data owner, permitted material, permitted purpose, authorized users, approved providers, processing location where required, model route, retention, return or deletion, and output recipients.
An NDA alone does not authorize every dataset or use. Depending on the material and parties, the required document may be a master agreement, data processing agreement, data use agreement, business associate agreement, security addendum or institution-supplied rider.
The accepted purpose controls use
Customer Material is used only to perform the Order under which it was accepted. It is not used for another customer’s work. It is not used for publication, product improvement, or training or fine-tuning a shared model without separate, express written permission.
Access is limited to the people and providers approved for the Order. An output is released only to a recipient authorized for the source material on which it depends.
Hosted payment keeps payment credentials with the provider
When hosted card or bank payment is offered, payment credentials are entered on the payment provider’s page. Varosync receives the billing information, transaction identifier and payment status needed to administer the Order. Complete card or bank-account credentials are not returned to Varosync through the hosted checkout flow.
Security review follows the proposed data route
An institution may request the security materials relevant to its proposed Order. Varosync first confirms the systems and information in scope. A reviewer then receives the current documents available for that route under appropriate confidentiality restrictions.
Include the institution, proposed Order or request reference, reviewer name, required deadline, proposed material class and security questionnaire or document list. Do not attach scientific files or patient information.
Control register
The following statements are verified for the current version. Additional controls are published only after their evidence is verified.
| Topic | Public statement |
|---|---|
| Public request boundary | Public forms accept only public, non-confidential descriptions. |
| Scientific intake separation | The order room and payment page are not scientific upload channels. |
| Hosted payment boundary | Payment credentials remain on the hosted provider page. |
| Access | Access to accepted Customer Material is limited by Order role. |
Security contact
Report a suspected security issue to security@varosync.com. Do not include patient information, credentials, live exploit code or Customer Material in the first message. We will provide a protected route if additional material is needed.