A wide view of an empty modern conference room at golden hour, two chairs slightly pulled out as if a conversation just ended.
Procurement & compliance pack

Everything your benefits committee needs — before a vendor call

Security posture, sample SOW, sample aggregate quarterly report, ERISA position, FAQ, OE templates, and reference guidance. Built specifically for HR and benefits leaders running a defensible procurement evaluation.

Need to share this with a committee? Email yourself the pack →

What's in this pack

Most caregiver-benefit vendors gate this material behind a sales call. We'd rather you have it on the desk before we talk — a 30-min conversation is more useful when you've already read the security posture and the sample SOW. If something specific is missing for your diligence process, reply to the welcome email and we'll send it directly.

1. Security & data-handling posture

Scope of data Averyn handles

Averyn handles caregiving administrative and operational data for the household it is engaged by: provider directory entries, appointment metadata, medication lists, vendor contact records, written household summaries, and documents the family uploads to the Record Vault (insurance cards, advance directives, hospital discharge paperwork, etc.). The Primary Contact for each household authorizes what is captured.

Averyn is not a clinical service, does not access electronic health records, does not provide medical advice, does not transmit data to clinical providers on a routine basis, and does not act as a HIPAA Covered Entity. Averyn operates as a household administrative service.

Storage and access architecture

Household data is stored in the Averyn portal (Record Vault), hosted in a major cloud provider (AWS us-east region by default; specific region pinning available on request for international engagements). All data at rest is encrypted (AES-256). All data in transit is encrypted (TLS 1.2+). Access is role-based and scoped to the navigator(s) assigned to the household plus authorized family members the Primary Contact has invited.

Employer access (what the employer sees)

For employer-sponsored or employer-listed engagements, the employer sees aggregate utilization reporting only — activation counts, time-to-first-deliverable, continuation rates, and (if surveyed) employee satisfaction scores. The employer does not see: which employees activated, what household situations are being coordinated, what records are in any given Record Vault, what providers or medications are involved, family member names, or any case-level detail. The privacy line is enforced at the data architecture, not just policy.

Authentication and access control

Email + password authentication with optional magic-link sign-in; account lockout on repeated failed attempts; session timeout configurable; multi-factor authentication available for households that request it. Navigator access is W2-employee role-scoped; contractor access (if applicable for surge coverage) is time-bound and audited.

Vendor and provider data

Averyn maintains a provider/vendor directory that supports household coordination. Provider information is collected from publicly available sources, household self-report, and prior coordination experience. Averyn does not sell or rent provider data, does not include sponsored placements, and does not receive referral fees from providers listed in any household coordination. The provider directory is an internal operational tool, not a monetizable asset.

Subprocessors

Major subprocessors include: AWS (cloud hosting), Supabase (managed Postgres + auth), Postmark (transactional email), Stripe (payment processing), Cal.com (calendar booking for navigator family touchpoints), and Twilio (SMS for time-sensitive coordination touchpoints). A full subprocessor list is available on request and is included in standard data-processing agreement (DPA) addenda where required.

Data retention and deletion

Household data is retained for the duration of the engagement plus a defined retention window (default 24 months post-engagement, per the Family Pact). Households can request earlier deletion of specific records or full data export at any time. Aggregate utilization data shared with employer sponsors is anonymized at source and does not contain individual records.

Incident response

Averyn's incident response process includes 72-hour notification commitments to affected households and employer sponsors for any incident with potential data exposure, regardless of statutory notification requirements. Notification includes scope, mitigation, and remediation steps. For employer-sponsored engagements, the sponsor's procurement contact is included in the notification chain by agreement.

Independent attestations

Averyn is a small private-pay-rooted service in early-stage growth; we do not currently hold a SOC 2 Type II attestation. We do operate with SOC-aligned controls (encrypted-at-rest, encrypted-in-transit, role-based access, audit logging, MFA-capable, named DPO equivalent) and are progressing toward formal attestation in alignment with employer-channel growth. Procurement teams that require SOC 2 as a precondition: we can speak to it directly and provide a realistic timeline for your evaluation cycle.

2. ERISA position

Averyn is a household administrative service, not an employee welfare benefit plan, not a HIPAA Covered Entity, and not a fiduciary under ERISA. The three employer-channel structures (voluntary listing, co-funded pilot, LSA-eligible) are designed to avoid creating ERISA-plan exposure:

  • Voluntary listing: The employer lists Averyn as a discount/preferred-rate vendor in the benefits portal. The employee contracts directly with Averyn and pays directly. The employer is not the payer, not the plan administrator, and does not collect premiums. Treated as a voluntary benefit / employer-discount arrangement under common safe-harbor patterns.
  • Co-funded pilot: The employer pre-funds a defined-budget pool of activations as a one-time strategic-initiative spend, not as an ongoing benefit promise. Each activation is a discrete transaction with the household. Properly structured as a non-ERISA arrangement; the SOW reflects this explicitly.
  • LSA-eligible: Averyn is added as a qualifying expense category in the employer's existing Lifestyle Spending Account. LSA programs themselves are not typically ERISA plans; adding a category does not change that posture. Employees elect to apply LSA dollars to Averyn engagement.

Each engagement type is documented in the relevant SOW or vendor agreement with the ERISA posture stated explicitly. We strongly recommend your benefits counsel review the specific structure you're considering against your existing plan documents; we'll provide whatever supporting documentation that review requires.

3. Sample SOW: small co-funded pilot

The text below is a structural sample — commercial terms, indemnification scope, governing law, and similar standard contract provisions are negotiated to your organization's preferred template. Use this to understand shape and scope before a procurement conversation.

SAMPLE — STRUCTURAL ILLUSTRATION ONLY

Statement of Work: Caregiver Coordination Pilot

Sponsor: [Employer name]
Vendor: Averyn Care, Inc.
Term: 12 months from effective date
Pilot pool: 10 funded activations

1. Scope of services

Averyn will deliver up to 10 Sponsored Launch Bundle activations to employees of Sponsor and their family members managing care for an aging or chronically ill loved one. Each activation includes: (a) Record Vault initialization, (b) 90 days of dedicated navigator coordination, (c) Care Continuity Plan deliverable at the end of the 90-day window, and (d) optional household continuation at preferred annual rates.

2. Eligibility & activation mechanics

Sponsor identifies eligible employees through [Sponsor's preferred mechanism: HR referral / employee self-nomination / benefits-portal request]. Sponsor confirms eligibility to Averyn. Averyn engages directly with the employee/family from that point. Sponsor does not receive case-level information during or after activation.

3. Pricing & payment

Sponsored Launch Bundle: a flat per-activation rate (Record Vault + 90 days of dedicated coordination). Co-pay split between Sponsor and Family is configurable (50/50 default; Sponsor-weighted alternatives available). Pre-funded pool: Sponsor pre-funds a set number of activations at execution; unused activations expire at end of term (no carry-over). Family co-pay collected directly by Averyn at activation; not invoiced to Sponsor. Exact figures and split options are confirmed in the 30-minute conversation and on the quote.

4. Reporting

Averyn delivers quarterly aggregate utilization reports to Sponsor's designated procurement / benefits contact. Reports include: activations to date, average time-to-Record-Vault, continuation rate after the 90-day funded window, and (where Sponsor has opted into a satisfaction survey at exit) aggregate satisfaction score. Reports do not contain individual employee names, household details, or case specifics. See sample report below.

5. Privacy & data handling

Household data is owned by the household. Sponsor does not receive case-level data under any circumstances. Privacy & data-handling architecture as described in the Procurement Pack and the standard DPA addendum.

6. Term, renewal, and termination

Twelve-month initial term. Renewal by mutual agreement at end of term, sized to actual utilization and Sponsor's evaluation. Either party may terminate for cause on 30 days' written notice. Pre-funded activations are non-refundable except in case of material breach by Averyn.

7. Standard contract provisions

Limitation of liability, indemnification, insurance (professional liability coverage maintained per industry standard), confidentiality, governing law, dispute resolution — per Sponsor's preferred contract template or Averyn's standard, as agreed.

A redlined version of your template can be produced in 1-2 business days. Larger pilot sizes (20, 50, 100 activations) scale linearly with discount available at higher volume.

4. Sample aggregate quarterly report

The mock below illustrates the shape of a real quarterly aggregate report Sponsor would receive. Numbers are illustrative; real reports reflect your pilot's actual utilization. No employee or household-level information appears in any quarterly report.

SAMPLE QUARTERLY REPORT — ILLUSTRATIVE ONLY

Caregiver Coordination Pilot — Q2 Aggregate Report

Sponsor: [Employer Name] · Pilot pool: 10 funded activations · Report period: April 1 – June 30

Activation summary

Activations this period
4 of 10
Cumulative: 6 of 10
Avg time to Record Vault
4.2 days
From activation to first delivered artifact

Continuation & engagement

Continuation rate
67%
Households continuing beyond 90-day funded window (n=3 eligible to date)
Active coordination households
5
In funded window or continuing

Satisfaction (opt-in survey at 60 days)

Net satisfaction (n=4 responses)
+88
Likelihood-to-recommend scale; ranges −100 to +100

Pilot utilization trajectory

At 6 of 10 activations cumulative through Q2, this pilot is on track to consume the funded pool by end of Q3 at current activation pace. If Sponsor anticipates additional demand, we recommend an early renewal conversation in early Q3 to avoid coverage gaps.

What is not included in this report (by design)

Employee identifiers, household composition, the loved one's condition or care situation, specific providers or vendors coordinated, document or record contents, or any case-level data. Aggregate-only reporting is a structural privacy commitment, not a discretionary choice.

Reports are delivered as PDF + dashboard view to Sponsor's designated procurement / benefits contact. Cadence is quarterly by default; monthly available on request for pilots with reporting-frequency requirements.

5. FAQ for benefits leaders

Eligibility & dependents

Who is eligible to activate? Any employee of Sponsor (within the eligible-population definition in the SOW) who is managing care for an aging parent, chronically ill spouse, adult sibling, or similar family member. The activator is the employee; the coordinated household is the family member's situation.

Are non-traditional family structures eligible? Yes — "family" is defined by the employee's relationship to the supported person, not by legal definitions of dependent. Step-parents, in-laws, partners' parents, chosen-family caregivers all qualify.

What if the employee is themselves the supported person? Less common but supported — an employee managing their own complex care situation (e.g., recent diagnosis, post-discharge recovery, chronic condition coordination) can activate as the supported person, with the navigator coordinating on their behalf.

Geography & language

Where can the supported loved one be located? Anywhere in the continental United States. Averyn operates remote-first; the navigator's location is independent of the household's. Active coordination outside the US is not currently supported.

What languages? Primary coordination language is English. Spanish-language navigator coordination is available on request. Other languages: please ask — we can usually accommodate via partner translation services for specific touchpoints but cannot promise full coordination in languages outside English/Spanish at this stage.

Scope & exclusions

What is explicitly out of scope? Averyn does not provide: clinical advice or medical guidance, emergency monitoring or 24/7 access, insurance navigation or benefits counseling, hands-on caregiving or home visits, legal advice, financial planning, or services requiring clinical licensure (nursing, social work case management). When a household need falls into one of these categories, the navigator helps find the right provider but does not perform the service itself.

What does the 90-day funded window actually cover? Record Vault setup and curation, household intake and Care Continuity Plan, ongoing coordination of appointments / vendors / providers as needs arise, written household updates to family, and the 90-day exit handoff (continuation plan or close-out). For most households, this covers an acute event end-to-end (e.g., discharge from a hospitalization with multiple specialist follow-ups) or initiates ongoing coordination that continues at preferred annual rates.

What happens if a household needs more than 90 days? The navigator surfaces this in week 6-8 and presents continuation options at the household's preferred annual rate. Most households who continue past 90 days had a complex enough situation that the Care Continuity Plan recommended ongoing coordination; this is normal and expected.

Reporting & integration

Can we integrate with our HRIS / benefits portal? Averyn currently supports listing in a benefits portal as a vendor; deeper HRIS integration is not standard but can be scoped for larger pilots if needed. Most engagements operate without HRIS integration.

Can we get monthly reports instead of quarterly? Yes — specify in the SOW. Default is quarterly because that's typically the right cadence for utilization signals to be meaningful; monthly is available where Sponsor's internal reporting cadence requires it.

Can the report be customized to our metrics? Within aggregate-reporting bounds (no individual-level data), yes — the report's metrics can be tailored to what your benefits committee is actually trying to learn.

Procurement timelines

What's a realistic procurement timeline? Voluntary listing: 1-2 weeks (vendor record + portal listing). Co-funded pilot: 4-6 weeks (full SOW review, security/legal review, contracting). LSA-eligible category addition: 1-3 weeks (depends on LSA administrator processes). Open Enrollment timing: most employer-channel activations cluster in the 4-8 weeks after OE; if you're targeting OE itself, start the procurement conversation by July for January OE.

6. Open Enrollment & employee-announcement templates

Three short templates Sponsor's benefits-communications team can adapt for their voice and channel. All three are positioned around the family member, not the employee — that framing has consistently outperformed "this is a benefit for caregivers like you" language in our pilot rollouts.

Template A: Open Enrollment announcement (broad workforce)

Subject: Something new in this year's benefits — for the people we're already taking care of

If you're helping coordinate care for an aging parent, a sibling, a spouse, or someone else important to you — we're adding a new benefit this year that's built specifically for that work.

Averyn is a caregiver-coordination service. Their navigators handle the administrative side of caregiving for your family: organizing medical records, scheduling specialists, coordinating with vendors, and keeping the rest of the family aligned with written updates.

It's structured as [voluntary listing at preferred rates / a co-funded pilot for up to 10 families / an eligible expense in the LSA program] — meaning [the cost is fully on you at a preferred rate / [Employer] funds part or all of the engagement / you can apply your LSA dollars to it].

If you'd like to learn more or activate, see the benefits portal > Family & Caregiver Support > Averyn. Or attend the 30-min info session on [date].

Your participation is confidential. [Employer] sees only aggregate utilization numbers, never who activates or what's happening in any household.

Template B: Partner / executive cohort (discreet, narrower audience)

Subject: Adding a quiet benefit to the partner package

We're adding Averyn Care to the partner-package benefits this year. Averyn is a caregiver-coordination service that operates as a household administrative layer — records, providers, vendors, family alignment — for partners or family members managing an aging or chronically ill loved one.

Two notes on how this works:

First, it's positioned as a voluntary benefit at preferred annual rates. The cost is on you, not on the partnership — the rate is confirmed on the activation call; coordination begins immediately on activation.

Second, participation is invisible at the partner table. The firm sees aggregate utilization counts only — no names, no households, no situations. You can activate without flagging anything to administration, the other partners, or HR.

If you'd like more detail or want to talk to someone before activating, contact [Partner-amenity benefits coordinator] directly. The 30-min activation call goes directly to Averyn, not through the firm.

Template C: Manager-to-employee referral (one-on-one outreach)

Subject: Something I wanted to mention — only if useful

This is a one-time mention, no follow-up unless you want one.

I know you've been carrying a lot at home with [parent / family member]. We added a benefit this year through a service called Averyn that handles the administrative side of caregiving — the calls, the records, the scheduling, the family updates. It's structured so the firm doesn't see who uses it, just aggregate counts.

You're not on a list. I'm not tracking this. I just wanted you to know it exists because I thought it might take some of the load off if it's useful.

Link to activate is in the benefits portal. Or just reply if you want me to forward the contact directly.

Adapt freely; if you want a customized version for a specific channel (Slack, intranet article, all-hands script), reply and we'll draft one for your voice and audience.

For the operational side of how these templates fit into a launch calendar, see the two-week rollout playbook — day-by-day owners, deliverables, and timing.

7. Reference contacts

Averyn is in the early-customer phase of the employer channel. Reference logos and case studies are accumulating in 2026 with first co-funded pilots. We can provide:

  • Direct conversations with founding-cohort family customers from the private-pay channel (with their permission), who can speak to the navigator-led coordination experience.
  • Anonymized case profiles illustrating the shape of household coordination work, the time-to-Record-Vault, and the kinds of family situations the service handles.
  • Employer-channel pilot references as they accumulate. First reference logos are anticipated for late 2026.

If your procurement process requires reference logos before a pilot decision, we'll discuss that timing directly — we'd rather be honest about where we are than overstate. The procurement-pack discipline of this page exists in part because we have to substitute documentation depth for the reference-logo depth larger competitors have accumulated; if that tradeoff doesn't work for your committee, the other vendors profiled in the buyer's guide are better-positioned to meet your requirement.

Email yourself the pack

Want this on your desk before the committee meeting?

Drop your work email and I'll send a personally-reviewed version of the procurement pack within 1 business day. If you have specific items your committee needs first (security posture, sample SOW, sample aggregate report), reply to the email with the priority and I'll send those directly.

One reply from me within 1 business day. Then a quiet, multi-month cadence with citable short reads. Unsubscribe in every email.

Or talk it through

A 30-min conversation usually covers everything written above plus the edge cases for your specific industry and the "this might not be a fit because…" questions directly.

Read the buyer's guide →