Skip to main content

Security Overview

Aventora operates an AI-powered customer engagement platform with layered security controls designed to protect customer data across Engagement Hub, Domain Assistant, and Aventora CRM. This overview summarizes our security posture for enterprise IT reviewers, procurement teams, and privacy officers.

This documentation is not a certification or attestation. Contractual commitments are defined in your services agreement and any executed data processing addendum. For a curated document set, see the Customer Security Package.


Security commitments

CommitmentSummary
Customer data ownershipCustomer data belongs to the customer; Aventora processes it only to deliver contracted services
No sale of dataAventora does not sell, rent, or license customer data
Encryption in transitTLS (1.2+) protects production API, administrative, and customer-facing traffic
Access controlRole-based access control and least privilege across platform and operations
Credential protectionAPI credentials and passwords protected using industry-standard cryptographic controls
Webhook integrityProvider signature validation on telephony and messaging webhooks
MFA for privileged accessMulti-factor authentication required for Aventora administrative and cloud accounts
Incident responseDocumented procedures for detection, containment, investigation, and customer notification
Subprocessor transparencyThird-party processors disclosed in the Subprocessor Annex

Platform security controls

Authentication and authorization

  • API credential authentication with industry-standard cryptographic protection and permission-scoped access
  • Session and token-based authentication for administrative and workspace users
  • Server-side authorization on protected routes
  • Provider signature validation on inbound telephony and messaging webhooks

Data protection

  • TLS encryption for data in transit across production services
  • Provider-supported encryption at rest for production data stores
  • Secrets managed through restricted deployment configuration; centralized vault services may be used depending on deployment model
  • Data classification and handling requirements in the Data Classification and Handling Policy

See Data Retention.

Operations and resilience

  • Managed deployments with health monitoring and controlled restarts
  • Logging and monitoring for security-relevant events
  • Backup and disaster recovery procedures for production environments
  • Vulnerability management and secure development practices (see Secure Development Lifecycle (SDLC) Policy)

See Incident Response.

Third-party integrations

Aventora integrates with telephony, AI, identity, and calendar providers using least-privilege credentials, encrypted transport, and webhook signature validation where supported. See the Subprocessor Annex.


Deployment flexibility

Aventora supports deployment models that address common enterprise requirements:

ModelDescription
Managed cloudManaged cloud deployments supporting Canadian and U.S. hosting options
Self-hostedCustomer-operated deployments available; implementation guides provided under agreement
Private cloud / on-premisesSupported for data residency and sovereignty; LLM and telephony providers are configurable

Customer-specific security, residency, and deployment requirements may be incorporated where agreed in writing. Contact security@aventora.ai for architecture and deployment documentation.


Core security documentation

DocumentDescription
Privacy NoticePublic privacy notice
Subprocessor AnnexThird-party processors
Vendor Management PolicyVendor/subprocessor contractual requirements and approval checklists
Information Security Risk Management PolicyFormal risk identification, assessment, treatment, and review program (Approved by Management)
ComplianceControl theme alignment (non-certification)
Incident ResponseIncident handling approach
Business ContinuityAvailability, backup/recovery overview, and annual BCP tabletop requirement
Disaster Recovery Tabletop Exercise2026 annual DR/BC tabletop evidence (completed August 11, 2026; discussion-based)
Data RetentionStorage and retention practices

Additional policies (privacy, data classification, API security, change management, and SDLC) are listed in the Customer Security Package.


Certifications

Aventora does not claim formal certification under SOC 2, ISO 27001, HIPAA, or PCI DSS in this documentation unless explicitly stated in a valid attestation report delivered under contract. See Compliance for control theme alignment.


AI and customer data

Conversation content is processed by configured third-party AI providers during active sessions. Customer data is not used to train general-purpose AI models unless explicitly agreed in writing. Provider data handling depends on your contract and deployment choices. See AI Governance Policy, AI System Technical Documentation, and Engagement Hub Features — AI and Customer Data.


Contact

For security questionnaires, architecture walkthroughs, or supplemental materials:


Changelog

DateChange
2026-08-11Corrected tabletop evidence date to August 11, 2026 (BCP-TT-2026-07); superseded premature August 1 tabletop-completion wording in linked materials.
2026-08-01Recorded Management approval of Information Security Risk Management Policy and Risk Assessment and Treatment Procedure.
2026-08-01Linked Disaster Recovery Tabletop Exercise and Business Continuity (tabletop date later corrected 2026-08-11).
2026-07-27Linked Information Security Risk Management Policy (Draft — Pending Management Approval).
2026-07-20Linked Secure Development Lifecycle (SDLC) Policy (Draft — Pending Management Approval).
2026-07-06Added AI System Technical Documentation.
2026-07-06Added AI Governance Policy.
2026-07-06Added Privacy Notice, Customer Security Package, and policy documents.