SECURITY & ARCHITECTURE

Know where the data goes.

Start with the boundary. Follow the sensitive fields, identify every recipient and agree on who operates each control.

REFERENCE ARCHITECTURE

Separate the original
from its everyday use.

A conceptual data flow. The physical boundary depends on your deployment.

CONTROLLED DATA ENVIRONMENT
01

Your application

Collects the source record and defines the task.

Selected personal fields ↓
02 / PROVYN

Vault & access controls

Original values and mappings. Retrieval requires authorization.

DOWNSTREAM WORKFLOWS
03

Applications & analytics

Tokens and selected business fields.

AI & verification

Protected context or evidence of a defined fact.

Review each outbound field. Original-value retrieval is a separate, permissioned path.

DEPLOYMENT RESPONSIBILITIES

Choose the boundary.
Agree on the ownership.

01 / ON-PREMISES

Inside your infrastructure.

Plan customer-operated infrastructure and key management. Define Provyn’s maintenance and support access with your security team.

02 / PRIVATE CLOUD

Within a dedicated environment.

Agree on the cloud account, network isolation, key owner and the division of monitoring and recovery responsibilities.

03 / PROVYN CLOUD

A managed deployment.

Confirm available regions, key options, operator access, retention and service terms for your specific use case.

THE SECURITY REVIEW

Ask for the evidence.

Use these questions to scope an architecture session. Deployment-specific answers and supporting materials should be agreed before production.

Key custody

Identify the key owner, rotation process and recovery procedure.

Key-management diagram and recovery exercise.

Access to originals

Define service identities, permissions and operator access.

Allowed and denied retrieval tests; a sample audit record.

Residency

Map primary storage, backups, logs and support access.

A region-specific deployment and data-flow diagram.

Retention & deletion

Specify how records, mappings and backups are handled.

A deletion procedure with retention windows and exceptions.

Continuity & exit

Agree on recovery targets, export format and responsibilities.

A restore test, an export example and applicable service terms.

Request a security review →

SCOPE & ASSUMPTIONS

Make the limits
part of the design.

START WITH ONE WORKFLOW

Map your first data workflow.

In a 30-minute architecture session, identify the fields to protect, the systems involved and the checks for a pilot.

Book a 30-minute demoOpens the booking form on provyn.cloudsales@provyn.cloud