Skip to main content

Compliance Alignment

Aventora designs its security and privacy program to support alignment with common enterprise frameworks and applicable privacy legislation. This document describes control theme alignment for security questionnaires and vendor assessments.

This is not a certification statement. Aventora does not claim formal certification under SOC 2, ISO 27001, HIPAA, PCI DSS, or other frameworks in this documentation unless explicitly stated in a valid attestation report delivered under contract.


Privacy legislation

Aventora's privacy program supports alignment with:

FrameworkRelevance
PIPEDA (Canada)Personal information protection; accountability, safeguards, limiting collection, individual access
GDPR / UK GDPRProcessor obligations, data subject rights, subprocessor transparency, transfer mechanisms
U.S. state privacy lawsWhere applicable to Aventora operations or customer configurations

See the Personal Data Privacy & Protection Policy, Vendor Management Policy, Privacy Notice, and Subprocessor Annex.


SOC 2 control themes

Aventora addresses common SOC 2 Trust Services Criteria themes through documented policies and technical controls:

Criteria areaAventora practices
Security (CC)Authentication, authorization, encryption in transit, vulnerability management, incident response
Availability (A)Containerized deployments, health monitoring, backup and recovery procedures
Confidentiality (C)Data classification, access control, secret management, least privilege
Processing integrity (PI)Input validation, server-side authorization, change management

Supporting documents: API Security Policy, Application Change Management Policy.


ISO 27001 principles

Aventora maintains operational practices aligned with information security management principles commonly evaluated in ISO 27001 assessments:

  • Access control at the application layer
  • Event logging and monitoring
  • Secure development and change management
  • Vendor and subprocessor management (Vendor Management Policy)
  • Documented incident response procedures

Sector-specific frameworks

FrameworkAventora position
HIPAANo general claim of HIPAA compliance; applies only where explicitly agreed in writing
PCI DSSNo claim of PCI DSS compliance; payment features do not constitute a cardholder data environment unless separately assessed

Customers with sector-specific requirements should discuss applicability during contracting.


Data residency

Default Aventora-managed deployments use AWS Canadian regions unless otherwise agreed in writing. Alternate managed regions, customer-managed/self-hosted deployments, and hybrid configurations are available per agreement. See Personal Data Privacy & Protection Policy — Data Residency.


Customer assessment support

Aventora provides documentation to support enterprise security and privacy assessments:

For supplemental materials or attestation requests: security@aventora.ai



Changelog

DateChange
2026-07-20Linked Vendor Management Policy for privacy, ISO vendor management, and assessment support.
2026-07-06Clarified deployment models and alternate managed regions in data residency section.
2026-07-06Initial publication of compliance alignment overview.