Compliance Alignment
Aventora designs its security and privacy program to support alignment with common enterprise frameworks and applicable privacy legislation. This document describes control theme alignment for security questionnaires and vendor assessments.
This is not a certification statement. Aventora does not claim formal certification under SOC 2, ISO 27001, HIPAA, PCI DSS, or other frameworks in this documentation unless explicitly stated in a valid attestation report delivered under contract.
Privacy legislation
Aventora's privacy program supports alignment with:
| Framework | Relevance |
|---|---|
| PIPEDA (Canada) | Personal information protection; accountability, safeguards, limiting collection, individual access |
| GDPR / UK GDPR | Processor obligations, data subject rights, subprocessor transparency, transfer mechanisms |
| U.S. state privacy laws | Where applicable to Aventora operations or customer configurations |
See the Personal Data Privacy & Protection Policy, Vendor Management Policy, Privacy Notice, and Subprocessor Annex.
SOC 2 control themes
Aventora addresses common SOC 2 Trust Services Criteria themes through documented policies and technical controls:
| Criteria area | Aventora practices |
|---|---|
| Security (CC) | Authentication, authorization, encryption in transit, vulnerability management, incident response |
| Availability (A) | Containerized deployments, health monitoring, backup and recovery procedures |
| Confidentiality (C) | Data classification, access control, secret management, least privilege |
| Processing integrity (PI) | Input validation, server-side authorization, change management |
Supporting documents: API Security Policy, Application Change Management Policy.
ISO 27001 principles
Aventora maintains operational practices aligned with information security management principles commonly evaluated in ISO 27001 assessments:
- Access control at the application layer
- Event logging and monitoring
- Secure development and change management
- Vendor and subprocessor management (Vendor Management Policy)
- Documented incident response procedures
Sector-specific frameworks
| Framework | Aventora position |
|---|---|
| HIPAA | No general claim of HIPAA compliance; applies only where explicitly agreed in writing |
| PCI DSS | No claim of PCI DSS compliance; payment features do not constitute a cardholder data environment unless separately assessed |
Customers with sector-specific requirements should discuss applicability during contracting.
Data residency
Default Aventora-managed deployments use AWS Canadian regions unless otherwise agreed in writing. Alternate managed regions, customer-managed/self-hosted deployments, and hybrid configurations are available per agreement. See Personal Data Privacy & Protection Policy — Data Residency.
Customer assessment support
Aventora provides documentation to support enterprise security and privacy assessments:
- Customer Security Package — curated document index
- Vendor Management Policy — vendor/subprocessor contractual requirements and approval checklists
- Privacy & Data Protection Executive Summary — questionnaire summary
- Data Processing Addendum Appendix — DPA template
For supplemental materials or attestation requests: security@aventora.ai
Related documentation
- Security Overview
- Data Classification and Handling Policy
- Vulnerability Management
- Incident Response
Changelog
| Date | Change |
|---|---|
| 2026-07-20 | Linked Vendor Management Policy for privacy, ISO vendor management, and assessment support. |
| 2026-07-06 | Clarified deployment models and alternate managed regions in data residency section. |
| 2026-07-06 | Initial publication of compliance alignment overview. |