The security of our neighbors’ data, and that of the agencies, health plans, and networks we serve, is our first priority.

People turn to Vivery when they need help getting food and other support. That trust carries a responsibility to protect their information with care and dignity. This page explains how we secure the Vivery platform, protect privacy, and use artificial intelligence responsibly.

U.S.-hosted on Microsoft AzureData stored and processed in U.S. data centers
Encrypted everywhereAES-256 at rest, TLS 1.2+ in transit
HIPAA business associatePHI protected under business associate agreements
Independently testedThird-party penetration testing; most recent August 2026
We never sell your dataNo sale or sharing for targeted advertising
No PII or PHI sent to AI modelsThird-party AI receives only minimum, non-identifying data

Our Security Program

Vivery is built and operated by AssetBlue Impact Technologies, PBC (ABIT) under a documented information security program. That program covers access control, encryption, data classification, vendor management, vulnerability management, incident response, and business continuity. Our policies are reviewed annually and approved by management, and our development team is based in the United States.

Infrastructure and hosting

  • Built on the Microsoft Azure cloud platform, using data centers only within the United States
  • Production backups are encrypted and stored in a separate U.S. region
  • Network segmentation separates internet-facing services from internal components
  • Continuous security posture monitoring with Microsoft Defender for Cloud

Data protection

  • Encryption at rest (AES-256) with keys managed in Azure Key Vault
  • Encryption in transit (TLS 1.2 or higher) for all web and API traffic
  • Sensitive data discovery and classification with Microsoft Purview
  • Data loss prevention controls on outbound traffic
  • We collect and use only the data described in our Privacy Policy

Identity and access

  • Single sign-on and multi-factor authentication through Microsoft Entra ID
  • Least-privilege, role-based access; production access is approval-based and limited
  • Access reviews at least annually, with access removed within 24 hours when no longer needed
  • Administrators accept our Terms of Use when their credentials are created, and again whenever the terms change

Secure development

  • A documented secure software development lifecycle with code review and automated testing
  • Staged releases through test and staging environments before production
  • Production data is not used for testing; test environments use synthetic, masked, or de-identified data
  • Application code is scanned for vulnerabilities before deployment

Testing and monitoring

  • Independent third-party penetration testing, most recently completed in August 2026
  • Ongoing vulnerability management and scanning of internet-facing systems
  • Centralized logging, auditing, and anomaly detection

People and training

  • Background checks for eligible personnel
  • Security and privacy training at onboarding and annually, with phishing awareness exercises
  • Confidentiality obligations and annual policy acknowledgment for all workforce members

Incident response

  • A documented incident response plan with defined roles, escalation, and notification procedures
  • We practice “what if” scenarios through tabletop exercises
  • If an incident affects your information, we notify you and our partners as required by law and contract

Business continuity

  • A business continuity and disaster recovery plan for the Vivery platform
  • Automated, encrypted backups with restore testing under our backup policy
  • Redundant Azure infrastructure designed for resilience

Privacy and HIPAA

Protecting health information

When Vivery is provided through a health plan, healthcare provider, or other HIPAA-covered organization, ABIT acts as that organization’s business associate. We protect health information as HIPAA and our business associate agreements require. Every vendor that handles protected health information on our behalf does so under its own business associate agreement.

Your information, your rights

  • We do not sell personal information or share it for targeted advertising
  • We keep information only as long as needed, and we delete closed-account data after 90 days unless the law or our contracts require us to keep it longer
  • You can request access to, correction of, or deletion of your information
  • Every Vivery page links to our Privacy Policy

Responsible Use of AI

Vivery uses artificial intelligence to help connect people with programs they may be eligible for and to keep them engaged with those programs. We apply the same care to AI as to the rest of the platform:

What AI does in Vivery

  • Program recommendations: our in-house models suggest programs that may fit a person’s needs, location, and schedule
  • Reminders and check-ins: an AI service helps time and word short in-app messages, using templates written by program staff
  • Translation: machine translation helps people use Vivery in their preferred language

Our safeguards

  • No personal information or PHI is sent to third-party AI models; they receive only the minimum, non-identifying data needed
  • The third-party AI services used in production run in Microsoft Azure in the United States, under contracts that prohibit using our data to train their models
  • Recommendations are suggestions only. AI never decides eligibility or denies services.
  • Data provided by our health plan partners is not used to train AI without their written authorization
  • People can turn off personalized recommendations at any time

A detailed AI Bill of Materials, describing each AI component, its data, and its safeguards, is available to customers and partners on request.

Subprocessors

We rely on a small number of trusted providers to deliver the Vivery platform. Each is reviewed under our vendor management program and contractually bound to protect the data it handles.

ProviderPurposeBusiness associate agreement
Microsoft AzureCloud hosting, storage, AI services (Azure OpenAI Service, Azure AI Translator), mappingYes
WebIT ServicesIT servicesYes
HubSpotCommunications platformYes
FormstackSurveys and formsYes
TwilioText messaging (SMS)Not applicable (no PHI)
SendGrid (Twilio)Email deliveryNot applicable (no PHI)
Branch.ioApp deep-linking and reportingNot applicable (no PHI)
WorkWaveDelivery route planningNot applicable (no PHI)

Health plan partners are notified of subprocessor changes as their agreements require.

Compliance and Documentation

Our security and privacy controls are designed to meet HIPAA Security and Privacy Rule requirements and are aligned with SOC 2 Trust Services Criteria. We regularly complete detailed security due-diligence reviews for health plan partners.

Customers and prospective partners can request our security documentation, including policy summaries, a penetration test summary, our AI Bill of Materials, and completed security questionnaires. Some documents require a nondisclosure agreement.

Reporting a Vulnerability

If you believe you have found a security vulnerability in Vivery, please email with a description and steps to reproduce it. We review every good-faith report, keep you informed as we investigate, and will not take legal action against researchers who act in good faith, avoid harming our users or data, and give us reasonable time to fix the issue before disclosing it publicly.

Questions?

For security, privacy, or compliance questions, or to request documentation, contact us at .

AssetBlue Impact Technologies, PBC · 351 W. Hubbard St., Suite 709, Chicago, IL 60654

To Top