Skip to main content

Aventora Customer Security Package

FieldValue
Document NameCustomer Security Package
Version1.5
Effective DateAugust 1, 2026
OwnerAventora Security
Review FrequencyAnnually
ClassificationInternal / Customer Shareable
Approval StatusApproved for publication — see Changelog

Purpose

This page is the index of customer-shareable security and privacy documentation for enterprise IT security reviews, vendor risk assessments, and procurement due diligence.

Documents listed here are suitable for sharing with enterprise customers unless marked otherwise. They are not certifications, attestations, or audit reports. Contractual commitments are defined in the applicable services agreement and any executed data processing addendum.

For security questionnaires, architecture walkthroughs, deployment guides, or supplemental materials: security@aventora.ai or sales@aventora.ai.


DocumentDescription
Security OverviewPlatform security commitments and control summary
Privacy NoticePublic privacy notice
Subprocessor AnnexThird parties that may process personal information
ComplianceControl theme alignment (non-certification)
Incident ResponseIncident handling approach
Business ContinuityAvailability, backup/recovery overview, and annual BCP tabletop exercise requirement
Disaster Recovery Tabletop Exercise2026 annual DR/BC tabletop evidence (completed August 11, 2026; discussion-based)
Data RetentionStorage and retention practices

Policy documents

Formal policies suitable for security and privacy reviews:

DocumentDescription
Data Classification and Handling PolicyInformation classification and handling requirements
Personal Data Privacy & Protection PolicyPrivacy commitments for personal information
Vendor Management PolicyVendor/subprocessor contractual requirements, due-diligence checklist, and contract review checklist
Information Security Risk Management PolicyFormal risk management program governance (Approved by Management)
Risk Assessment and Treatment Procedure5×5 risk scoring methodology and treatment/acceptance templates (Approved by Management)
AI Governance PolicyResponsible AI usage, data handling, and provider management
AI System Technical DocumentationTechnical AI architecture, data flows, and component reference for due diligence
Application Change Management PolicyControlled change practices for production systems
Secure Development Lifecycle (SDLC) PolicySecure development, review, testing, and release practices (Draft — Pending Management Approval)
API Security PolicyAPI authentication, authorization, and integration security
Government and Public Authority Data Request PolicyLawful government and public authority access requests

Executive summaries and contractual annexes

DocumentDescription
Privacy & Data Protection Executive SummaryOne-page privacy overview
Data Processing Addendum AppendixSupplemental DPA terms and processing details

Supplemental materials (on request)

Architecture diagrams, data-flow documentation, deployment guides, and infrastructure configuration standards are available through your account team or security@aventora.ai.


Review focusSuggested documents
Initial vendor questionnairePrivacy Executive Summary, Security Overview, Subprocessor Annex
Data protection / privacy assessmentPersonal Data Privacy & Protection Policy, Vendor Management Policy, DPA Appendix, Data Classification and Handling Policy, Government and Public Authority Data Request Policy
Information security assessmentSecurity Overview, Data Classification and Handling Policy, Vendor Management Policy, Information Security Risk Management Policy, Risk Assessment and Treatment Procedure, API Security Policy, Secure Development Lifecycle (SDLC) Policy, Compliance, Incident Response
Vendor / subprocessor questionnaireVendor Management Policy, Subprocessor Annex, DPA Appendix, Personal Data Privacy & Protection Policy (Section 24)
AI governance / responsible AI reviewAI Governance Policy, AI System Technical Documentation, Subprocessor Annex, Integration Security
Full due diligenceAll documents listed above plus supplemental materials on request

Export and delivery

Documents are published at docs.aventora.ai/security. For offline delivery:

  1. Share direct links to the documents above, or
  2. Request a bundled export from security@aventora.ai.

Note: Aventora does not claim SOC 2, ISO 27001, PCI-DSS, HIPAA, or similar formal certifications unless explicitly stated in a valid attestation report. See Compliance.


Changelog

DateChange
2026-08-11Corrected Disaster Recovery Tabletop Exercise listing to August 11, 2026 completion (BCP-TT-2026-07); superseded premature August 1 tabletop-completion wording.
2026-08-01Recorded Management approval of Information Security Risk Management Policy and Risk Assessment and Treatment Procedure. Detailed risk register remains internal and may be shared under SOW/pilot confidentiality. Version 1.5.
2026-08-01Added Disaster Recovery Tabletop Exercise to core documents (date later corrected 2026-08-11). Version 1.4.
2026-07-27Added Business Continuity (including annual BCP tabletop exercise requirement) to core documents. Detailed exercise records remain internal.
2026-07-27Added Information Security Risk Management Policy and Risk Assessment and Treatment Procedure (Draft — Pending Management Approval) to policy documents and information security assessment index. Detailed risk register remains internal.
2026-07-20Added Vendor Management Policy (standard vendor/subprocessor contractual requirements and approval checklists) to policy documents and review-type index.
2026-07-20Added Secure Development Lifecycle (SDLC) Policy (Draft — Pending Management Approval) to policy documents and information security assessment index.
2026-07-06Updated published docs site URL from docs.aventora.app to docs.aventora.ai.
2026-07-06Added Government and Public Authority Data Request Policy to policy documents and privacy assessment index.
2026-07-06Added AI System Technical Documentation to policy documents and AI governance review index.
2026-07-06Added AI Governance Policy to policy documents and review-type index.
2026-07-06Initial Customer Security Package index.