We help organizations build resilience — so our own platform must lead by example. Here is how we protect your data and maintain the security of the Avsentia platform.
Avsentia does not store customer BC/DR plans by default. Plans generated through Dave are session-only — when your session ends, the output is not retained on our servers. This is a deliberate architectural choice that dramatically reduces your data exposure risk. Offsite storage is available as an explicit, paid opt-in for organizations that need it.
Trust Services Criteria implementation status
Access Control
MFA enforced for all admins; user TOTP enrollment available
System Operations
Sentry + Vercel + Supabase audit logs; IRP documented
Change Management
PR-required GitHub workflow; branch protection enabled
Vendor Management
All vendors SOC 2 Type II certified; reports on file
Confidentiality
No persistent BC/DR plan storage by default; AES-256 at rest
Availability
99.9% SLA target; RPO < 1hr, RTO < 4hr
Privacy
Privacy Policy published; CCPA/GDPR data subject rights process in place
Formal SOC 2 Type I audit is planned. Enterprise customers may request our security documentation package by contacting security@avsentia.com.
All data is encrypted in transit and at rest using industry-standard algorithms.
| Data Type | Method | Details |
|---|---|---|
| Data in Transit | TLS 1.2+ | Enforced by Vercel edge network on all connections |
| Data at Rest | AES-256 | Supabase/PostgreSQL managed encryption |
| Passwords | bcrypt | Never stored in plaintext; hashed via Supabase Auth |
| API Secrets | Env vault | All secrets stored in Vercel encrypted environment variables — never in source code |
| Session Tokens | JWT (HS256) | Short-lived tokens with automatic expiry and rotation |
Layered access controls enforce least-privilege access across the entire platform.
Every vendor with access to our infrastructure or customer data holds a current SOC 2 Type II certification.
We welcome security researchers who responsibly disclose vulnerabilities in the Avsentia platform. If you believe you have found a security issue, please report it to us privately before public disclosure.
Please do not access customer data, disrupt production services, or publicly disclose findings before coordinating with us. We commit to no legal action against good-faith researchers.
Security Team
security@avsentia.comEnterprise customers may request our full security documentation package, SOC 2 reports from our vendors, and a security questionnaire response.