Aventora Customer Security Package
| Field | Value |
|---|---|
| Document Name | Customer Security Package |
| Version | 1.5 |
| Effective Date | August 1, 2026 |
| Owner | Aventora Security |
| Review Frequency | Annually |
| Classification | Internal / Customer Shareable |
| Approval Status | Approved for publication — see Changelog |
Purpose
This page is the index of customer-shareable security and privacy documentation for enterprise IT security reviews, vendor risk assessments, and procurement due diligence.
Documents listed here are suitable for sharing with enterprise customers unless marked otherwise. They are not certifications, attestations, or audit reports. Contractual commitments are defined in the applicable services agreement and any executed data processing addendum.
For security questionnaires, architecture walkthroughs, deployment guides, or supplemental materials: security@aventora.ai or sales@aventora.ai.
Core documents (recommended for all reviews)
| Document | Description |
|---|---|
| Security Overview | Platform security commitments and control summary |
| Privacy Notice | Public privacy notice |
| Subprocessor Annex | Third parties that may process personal information |
| Compliance | Control theme alignment (non-certification) |
| Incident Response | Incident handling approach |
| Business Continuity | Availability, backup/recovery overview, and annual BCP tabletop exercise requirement |
| Disaster Recovery Tabletop Exercise | 2026 annual DR/BC tabletop evidence (completed August 11, 2026; discussion-based) |
| Data Retention | Storage and retention practices |
Policy documents
Formal policies suitable for security and privacy reviews:
| Document | Description |
|---|---|
| Data Classification and Handling Policy | Information classification and handling requirements |
| Personal Data Privacy & Protection Policy | Privacy commitments for personal information |
| Vendor Management Policy | Vendor/subprocessor contractual requirements, due-diligence checklist, and contract review checklist |
| Information Security Risk Management Policy | Formal risk management program governance (Approved by Management) |
| Risk Assessment and Treatment Procedure | 5×5 risk scoring methodology and treatment/acceptance templates (Approved by Management) |
| AI Governance Policy | Responsible AI usage, data handling, and provider management |
| AI System Technical Documentation | Technical AI architecture, data flows, and component reference for due diligence |
| Application Change Management Policy | Controlled change practices for production systems |
| Secure Development Lifecycle (SDLC) Policy | Secure development, review, testing, and release practices (Draft — Pending Management Approval) |
| API Security Policy | API authentication, authorization, and integration security |
| Government and Public Authority Data Request Policy | Lawful government and public authority access requests |
Executive summaries and contractual annexes
| Document | Description |
|---|---|
| Privacy & Data Protection Executive Summary | One-page privacy overview |
| Data Processing Addendum Appendix | Supplemental DPA terms and processing details |
Supplemental materials (on request)
Architecture diagrams, data-flow documentation, deployment guides, and infrastructure configuration standards are available through your account team or security@aventora.ai.
Recommended package by review type
| Review focus | Suggested documents |
|---|---|
| Initial vendor questionnaire | Privacy Executive Summary, Security Overview, Subprocessor Annex |
| Data protection / privacy assessment | Personal Data Privacy & Protection Policy, Vendor Management Policy, DPA Appendix, Data Classification and Handling Policy, Government and Public Authority Data Request Policy |
| Information security assessment | Security Overview, Data Classification and Handling Policy, Vendor Management Policy, Information Security Risk Management Policy, Risk Assessment and Treatment Procedure, API Security Policy, Secure Development Lifecycle (SDLC) Policy, Compliance, Incident Response |
| Vendor / subprocessor questionnaire | Vendor Management Policy, Subprocessor Annex, DPA Appendix, Personal Data Privacy & Protection Policy (Section 24) |
| AI governance / responsible AI review | AI Governance Policy, AI System Technical Documentation, Subprocessor Annex, Integration Security |
| Full due diligence | All documents listed above plus supplemental materials on request |
Export and delivery
Documents are published at docs.aventora.ai/security. For offline delivery:
- Share direct links to the documents above, or
- Request a bundled export from security@aventora.ai.
Note: Aventora does not claim SOC 2, ISO 27001, PCI-DSS, HIPAA, or similar formal certifications unless explicitly stated in a valid attestation report. See Compliance.
Changelog
| Date | Change |
|---|---|
| 2026-08-11 | Corrected Disaster Recovery Tabletop Exercise listing to August 11, 2026 completion (BCP-TT-2026-07); superseded premature August 1 tabletop-completion wording. |
| 2026-08-01 | Recorded Management approval of Information Security Risk Management Policy and Risk Assessment and Treatment Procedure. Detailed risk register remains internal and may be shared under SOW/pilot confidentiality. Version 1.5. |
| 2026-08-01 | Added Disaster Recovery Tabletop Exercise to core documents (date later corrected 2026-08-11). Version 1.4. |
| 2026-07-27 | Added Business Continuity (including annual BCP tabletop exercise requirement) to core documents. Detailed exercise records remain internal. |
| 2026-07-27 | Added Information Security Risk Management Policy and Risk Assessment and Treatment Procedure (Draft — Pending Management Approval) to policy documents and information security assessment index. Detailed risk register remains internal. |
| 2026-07-20 | Added Vendor Management Policy (standard vendor/subprocessor contractual requirements and approval checklists) to policy documents and review-type index. |
| 2026-07-20 | Added Secure Development Lifecycle (SDLC) Policy (Draft — Pending Management Approval) to policy documents and information security assessment index. |
| 2026-07-06 | Updated published docs site URL from docs.aventora.app to docs.aventora.ai. |
| 2026-07-06 | Added Government and Public Authority Data Request Policy to policy documents and privacy assessment index. |
| 2026-07-06 | Added AI System Technical Documentation to policy documents and AI governance review index. |
| 2026-07-06 | Added AI Governance Policy to policy documents and review-type index. |
| 2026-07-06 | Initial Customer Security Package index. |