Your data stays
in your Site.
Tenant isolation, one enforced permission system, encrypted transport, and infrastructure operated by Trivena, described honestly and without certification theatre.
Per-tenant isolation · Permission-aware AI · Managed backups & monitoring
What we will and will not claim
Plenty of vendors put a wall of badges on this page. We are a young company, so instead of implying audits we have not completed, we describe exactly how the platform is built and how we run it.
If your procurement process needs specific commitments, ask us. We would rather negotiate real terms than publish a comforting graphic.
One tenant, one boundary.
Multi-tenancy in Trivena means many isolated Sites on one platform, not many companies inside one database.
One Site per customer
Every customer runs in their own Site with its own database. There is no shared application database holding several companies' records.
No cross-tenant queries
Requests are resolved to a single Site before any business logic runs, so a query cannot span tenants by accident.
Separate credentials
Each Site has its own database credentials and configuration, managed by the control plane rather than shared by hand.
Isolated background work
Queues and scheduled jobs execute in the context of a Site, so async work carries the same boundary as a web request.
Permissions enforced once.
The permission system belongs to the platform, so every application, API call, and AI request reads the same rules.
Roles & permissions
Access is granted through roles, down to record type, row, and field level, using the same rules for the UI, the API, and AI.
Enforced once
Permissions live in the platform, not in each application, so a new app inherits your access model instead of inventing one.
Workflow approvals
Sensitive actions such as purchases above a threshold, leave approvals, and document submission route through configurable approval chains.
User lifecycle
Disable a person once and their access to every app in the Site ends. One identity, one off-boarding step.
Activity trail
Business events are stored as documents with their own history, which makes review a matter of reading records rather than reconstructing them.
Customer portal scoping
External users, such as customers raising tickets, see only their own records, through a separate portal surface.
How we run the infrastructure.
These practices are part of Trivena Cloud for every customer, on every plan.
Encrypted transport
All traffic to Sites is served over HTTPS with certificates issued and renewed automatically, and HSTS enabled.
Managed patching
Platform, application, and OS-level updates are applied by Trivena as part of running Cloud, not left to the customer.
Automated backups
Site databases and files are backed up on a schedule so recovery is a procedure rather than an improvisation.
Continuous monitoring
Control plane, workers, proxies, and database hosts are monitored around the clock, with results published publicly.
Least-privilege operations
Administrative access to infrastructure is limited to the people who operate it, over authenticated channels.
Separated environments
Test and staging Sites are separate tenants, so evaluating a change never touches production data.
How AI is governed.
- AI runs as the user
- Trivena AI executes in the context of the requesting user's permissions. If a person cannot open a record, AI cannot read it, summarize it, or cite it for them.
- Site-scoped context
- AI features operate inside the boundary of a single Site. One customer's data is never used as context for another customer's request.
- Human in the loop
- AI drafts, suggests, and proposes. People review and approve. Automations built from AI suggestions plug into the same approval chains as everything else.
- Provider flexibility
- Trivena AI works with leading AI providers rather than being locked to one. An enterprise option to bring your own model or keys is planned.
- Not training on your data
- Your business records are used to answer your questions, not to train a shared model across customers.
Found something? Email us with steps to reproduce and we will confirm receipt, investigate, and keep you updated on the fix.
CLOUD@TYNKTECH.NL →Availability is published rather than described. The same monitors we watch internally are visible to you.
VIEW SYSTEM STATUS →Security questions.
Yes. Each customer gets their own Site with its own database. Isolation comes from the architecture, because a request is resolved to one Site before any business logic runs.
Administrative access to infrastructure is limited to the people who operate Trivena Cloud, and it exists to keep your Site running. We do not browse customer business data as a matter of course, and support work happens on request.
We are not going to claim certifications we do not hold. Trivena is a young company; what we can describe honestly is our architecture, our operational practices, and our willingness to answer specific questions in detail. Enterprise agreements can include the commitments you need in writing.
No. Trivena AI runs through the same permission system as any user in your Site. Permission-awareness is a property of the platform, not a feature toggle on the AI.
Site databases and files are backed up automatically on a schedule as part of Trivena Cloud. Restoring is an operation we run for you.
Yes. See the data processing agreement page, and contact us for a signed version covering your specific processing.
Email cloud@tynktech.nl with the details. We would much rather hear about a problem from you than discover it later.
Need details for procurement?
Send us your security questionnaire or the commitments you need. We answer specifically, in writing.
Or email cloud@tynktech.nl