Security Overview
Aventora operates an AI-powered customer engagement platform with layered security controls designed to protect customer data across Engagement Hub, Domain Assistant, and Aventora CRM. This overview summarizes our security posture for enterprise IT reviewers, procurement teams, and privacy officers.
This documentation is not a certification or attestation. Contractual commitments are defined in your services agreement and any executed data processing addendum. For a curated document set, see the Customer Security Package.
Security commitments
| Commitment | Summary |
|---|---|
| Customer data ownership | Customer data belongs to the customer; Aventora processes it only to deliver contracted services |
| No sale of data | Aventora does not sell, rent, or license customer data |
| Encryption in transit | TLS (1.2+) protects production API, administrative, and customer-facing traffic |
| Access control | Role-based access control and least privilege across platform and operations |
| Credential protection | API credentials and passwords protected using industry-standard cryptographic controls |
| Webhook integrity | Provider signature validation on telephony and messaging webhooks |
| MFA for privileged access | Multi-factor authentication required for Aventora administrative and cloud accounts |
| Incident response | Documented procedures for detection, containment, investigation, and customer notification |
| Subprocessor transparency | Third-party processors disclosed in the Subprocessor Annex |
Platform security controls
Authentication and authorization
- API credential authentication with industry-standard cryptographic protection and permission-scoped access
- Session and token-based authentication for administrative and workspace users
- Server-side authorization on protected routes
- Provider signature validation on inbound telephony and messaging webhooks
Data protection
- TLS encryption for data in transit across production services
- Provider-supported encryption at rest for production data stores
- Secrets managed through restricted deployment configuration; centralized vault services may be used depending on deployment model
- Data classification and handling requirements in the Data Classification and Handling Policy
See Data Retention.
Operations and resilience
- Managed deployments with health monitoring and controlled restarts
- Logging and monitoring for security-relevant events
- Backup and disaster recovery procedures for production environments
- Vulnerability management and secure development practices (see Secure Development Lifecycle (SDLC) Policy)
See Incident Response.
Third-party integrations
Aventora integrates with telephony, AI, identity, and calendar providers using least-privilege credentials, encrypted transport, and webhook signature validation where supported. See the Subprocessor Annex.
Deployment flexibility
Aventora supports deployment models that address common enterprise requirements:
| Model | Description |
|---|---|
| Managed cloud | Managed cloud deployments supporting Canadian and U.S. hosting options |
| Self-hosted | Customer-operated deployments available; implementation guides provided under agreement |
| Private cloud / on-premises | Supported for data residency and sovereignty; LLM and telephony providers are configurable |
Customer-specific security, residency, and deployment requirements may be incorporated where agreed in writing. Contact security@aventora.ai for architecture and deployment documentation.
Core security documentation
| Document | Description |
|---|---|
| Privacy Notice | Public privacy notice |
| Subprocessor Annex | Third-party processors |
| Vendor Management Policy | Vendor/subprocessor contractual requirements and approval checklists |
| Information Security Risk Management Policy | Formal risk identification, assessment, treatment, and review program (Approved by Management) |
| Compliance | Control theme alignment (non-certification) |
| Incident Response | Incident handling approach |
| Business Continuity | Availability, backup/recovery overview, and annual BCP tabletop requirement |
| Disaster Recovery Tabletop Exercise | 2026 annual DR/BC tabletop evidence (completed August 11, 2026; discussion-based) |
| Data Retention | Storage and retention practices |
Additional policies (privacy, data classification, API security, change management, and SDLC) are listed in the Customer Security Package.
Certifications
Aventora does not claim formal certification under SOC 2, ISO 27001, HIPAA, or PCI DSS in this documentation unless explicitly stated in a valid attestation report delivered under contract. See Compliance for control theme alignment.
AI and customer data
Conversation content is processed by configured third-party AI providers during active sessions. Customer data is not used to train general-purpose AI models unless explicitly agreed in writing. Provider data handling depends on your contract and deployment choices. See AI Governance Policy, AI System Technical Documentation, and Engagement Hub Features — AI and Customer Data.
Contact
For security questionnaires, architecture walkthroughs, or supplemental materials:
- Security and privacy: security@aventora.ai
- Commercial and onboarding: sales@aventora.ai
Changelog
| Date | Change |
|---|---|
| 2026-08-11 | Corrected tabletop evidence date to August 11, 2026 (BCP-TT-2026-07); superseded premature August 1 tabletop-completion wording in linked materials. |
| 2026-08-01 | Recorded Management approval of Information Security Risk Management Policy and Risk Assessment and Treatment Procedure. |
| 2026-08-01 | Linked Disaster Recovery Tabletop Exercise and Business Continuity (tabletop date later corrected 2026-08-11). |
| 2026-07-27 | Linked Information Security Risk Management Policy (Draft — Pending Management Approval). |
| 2026-07-20 | Linked Secure Development Lifecycle (SDLC) Policy (Draft — Pending Management Approval). |
| 2026-07-06 | Added AI System Technical Documentation. |
| 2026-07-06 | Added AI Governance Policy. |
| 2026-07-06 | Added Privacy Notice, Customer Security Package, and policy documents. |