Get in touch
Legal and trust/Security and Trust

Security and Trust

Revised 21 August 2026·Version history

The first security decision is what Varosync is allowed to receive. Public requests, commercial records and scientific evidence use different channels. Private evidence moves only after Varosync accepts the material and the governing documents identify its permitted use.

Keep restricted material out of the public request

The public configurator accepts a public description of the decision and program. Do not submit patient information, unpublished results, MNPI, data-room material, export-controlled material or information you are not authorized to disclose.

A submitted request is reviewed for fit. It is not a secure intake channel and does not create an Order.

The order room handles the purchase

The private order room may hold the Order, organization and role information, agreement status, procurement instructions, billing records, payment status and project-administration answers. It is not the scientific workspace. Research files and patient information do not belong in the order room, on a payment page, in a support request or in ordinary email.

Private evidence requires written authorization

Before private evidence moves, Varosync determines whether the proposed material can be accepted for the Order. The applicable documents identify the data owner, permitted material, permitted purpose, authorized users, approved providers, processing location where required, model route, retention, return or deletion, and output recipients.

An NDA alone does not authorize every dataset or use. Depending on the material and parties, the required document may be a master agreement, data processing agreement, data use agreement, business associate agreement, security addendum or institution-supplied rider.

The accepted purpose controls use

Customer Material is used only to perform the Order under which it was accepted. It is not used for another customer’s work. It is not used for publication, product improvement, or training or fine-tuning a shared model without separate, express written permission.

Access is limited to the people and providers approved for the Order. An output is released only to a recipient authorized for the source material on which it depends.

Hosted payment keeps payment credentials with the provider

When hosted card or bank payment is offered, payment credentials are entered on the payment provider’s page. Varosync receives the billing information, transaction identifier and payment status needed to administer the Order. Complete card or bank-account credentials are not returned to Varosync through the hosted checkout flow.

Security review follows the proposed data route

An institution may request the security materials relevant to its proposed Order. Varosync first confirms the systems and information in scope. A reviewer then receives the current documents available for that route under appropriate confidentiality restrictions.

Request security review

Include the institution, proposed Order or request reference, reviewer name, required deadline, proposed material class and security questionnaire or document list. Do not attach scientific files or patient information.

Control register

The following statements are verified for the current version. Additional controls are published only after their evidence is verified.

TopicPublic statement
Public request boundaryPublic forms accept only public, non-confidential descriptions.
Scientific intake separationThe order room and payment page are not scientific upload channels.
Hosted payment boundaryPayment credentials remain on the hosted provider page.
AccessAccess to accepted Customer Material is limited by Order role.

Security contact

Report a suspected security issue to security@varosync.com. Do not include patient information, credentials, live exploit code or Customer Material in the first message. We will provide a protected route if additional material is needed.