Security & Governance

Clear answers before you commit.

Sorenn designs and builds custom software, automation, and applied AI for established organizations. This page answers the questions buyers raise most often about data, access, AI controls, and accountability.

If your technology, procurement, or risk team has specific requirements, you can review them with us before an engagement is scoped.

Four questions, answered directly.

Each answer describes how Sorenn approaches every engagement. Specific terms, such as retention periods, support coverage, and response expectations, depend on your requirements and are set out in the agreement for each engagement.

01 Your data

What information does Sorenn need, and who decides how it is handled?

Sorenn asks for the information a workflow needs to run. Before anything is built, the data sources, fields, and movements between systems are identified and reviewed with your team. Retention and deletion follow your organization’s policies, and handling requirements are recorded in the engagement documents.

What this means for you: you see and approve what the system uses before it depends on it.

Retention periods, storage location, and any regulatory or internal-policy requirements are confirmed while the engagement is scoped and written into its agreement.

02 Access

Who receives access, and how is that access managed?

Your organization grants access to the people and systems the work requires. Roles and access levels are defined in the specification before build, and accounts and environments are set up in your organization’s name where the engagement allows. How and when Sorenn’s access is removed is agreed in advance.

What this means for you: control over who can reach your systems stays with your team.

Access to third-party services follows your existing vendor contracts. If a tool needs to be added, your team decides whether and under which account.

03 AI controls

Who authorizes sensitive actions, and what happens when an AI workflow encounters an exception?

Your team decides which actions need human approval and who gives it. Each AI workflow works within permissions and limits defined before a pilot. When an input is missing, unclear, or outside those limits, the item waits for a named person with the reason attached instead of being processed.

What this means for you: consequential decisions stay with people you designate.

Inputs, outputs, and human decisions are recorded so your team can review what the system did. Results are measured on your own examples before release, and the review schedule after launch is agreed per engagement.

04 Changes, issues, and transition

Who is accountable when something changes or goes wrong, and how are support and transition responsibilities established?

Changes are accepted by your team before release and recorded with their reason and approver. Escalation contacts and post-launch support are named in the agreement before launch. At transition, your team receives documentation and a walkthrough so it can operate and change the system.

What this means for you: accountability is written down before you depend on the system.

Maintenance coverage, response expectations, and any warranty are defined for each engagement and set out in its agreement.

Review your requirements with us.

Request a Briefing and note the topic in your request. Your technology, legal, procurement, or risk leads are welcome to join the conversation.

  • A security or governance question
  • Procurement or vendor requirements
  • Your organization’s security questionnaire, to review together
Request a Briefing