HomeTrust & Legal CenterData Protection & Security Statement
Trust, Privacy & Security Center

Data Protection & Security Statement

Transparent details on how we safeguard client data, maintain operational integrity, and enforce strict security controls across custom software, AI, cloud, data engineering, analytics, and security engagements.

Last updated: August 24, 2026Scope: Software, AI, Data Engineering, Cloud, Analytics & Security Services

Our Security Standard & Philosophy

We apply industry-standard security practices including encrypted communication, access controls, secure authentication, and regular backups.

As an engineering agency delivering custom software, AI integrations, data pipelines, cloud solutions, analytics platforms, and security advisory, we believe transparency is paramount. We do not make exaggerated or impossible security claims—such as claiming any system is "100% unhackable" or "flawless." Instead, we build multi-layered security controls into every stage of the software development lifecycle (SDLC) and infrastructure deployment.

1. Where Customer Data is Stored

Customer data location depends on the architecture selected for your specific project (cloud SaaS, client-hosted infrastructure, or hybrid deployment). By default, our client solutions leverage tier-1 cloud providers equipped with physical security controls, ISO 27001, SOC 2 Type II, and PCI-DSS compliance certifications.

Managed Cloud Infrastructure

Web applications and edge endpoints are hosted on high-availability global cloud platforms (such as Vercel, AWS, or GCP). Application servers are deployed within isolated Virtual Private Clouds (VPC) or container environments.

Data Residency & Databases

Structured databases (e.g. PostgreSQL, Supabase, MySQL) and object storage buckets are provisioned in client-specified geographical regions (e.g. EU, US, or South Africa data centers) to satisfy local regulatory requirements.

2. Who Can Access Customer Data

We strictly restrict human access to production databases and client project repositories following the Principle of Least Privilege (PoLP).

  • Role-Based Access Control (RBAC): Only engineers explicitly assigned to a client engagement receive access permissions required for support, maintenance, or debugging.
  • Confidentiality Obligations: All AVS engineers and consultants sign strict Non-Disclosure Agreements (NDAs) and undergo security policy training prior to onboard handling of code or client databases.
  • Zero Data Monetization: We never sell, lease, rent, or trade client data, source code, or proprietary datasets to third parties under any circumstances.

3. Backups & Disaster Recovery

To guard against hardware failure, corruption, or unintentional loss, automated backup workflows are configured for all production databases managed by AVS.

Automated Snapshots

Daily automated snapshots with Point-in-Time Recovery (PITR) enabled for transactional databases.

Redundant Storage

Backups are stored in geographically separated object storage designed for 99.999999999% (11 9s) durability.

Restoration Tests

Periodic restoration validation drills to ensure Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are met.

4. Authentication & Credentials

Security begins with robust access verification across internal developer accounts and application user management systems:

Internal Engineering Security

Mandatory Multi-Factor Authentication (MFA) via hardware security keys or authenticator apps across all developer accounts, code repositories, cloud consoles, and secrets vaults. Password reuse is strictly forbidden.

Application Security Built for Clients

When engineering user authentication systems for clients, we implement industry-standard identity protocols—including OAuth 2.0 / OpenID Connect, JWT tokens with short time-to-live (TTL), secure password hashing (Argon2 or bcrypt), rate-limiting against brute force attacks, and HTTP-only CSRF-protected cookies.

5. Encryption Standards (In Transit & At Rest)

All data moving across networks or stored on disk is protected using strong cryptographic algorithms.

Transit

Encryption in Transit

All network communication, Web APIs, and client-server traffic mandate Transport Layer Security (TLS 1.2 or TLS 1.3) with modern cipher suites. Plain HTTP requests are automatically redirected to HTTPS with HSTS headers enforced.

Rest

Encryption at Rest

Database volumes, file attachments, and snapshot backups are encrypted at rest using AES-256 (Advanced Encryption Standard). API keys and secrets are securely stored in KMS vaults or encrypted environment variables.

6. Data Retention & Secure Disposal

We retain customer project data and telemetry only as long as necessary to fulfill contractual obligations, provide active support, or maintain compliance with legal requirements.

  • Active Engagements: Operational data is stored for the lifecycle of the active client agreement.
  • Post-Termination Deletion: Upon completion or termination of a contract, client data hosted in AVS-controlled staging environments is deleted within 30 days upon client written request.
  • System Logs: Operational access logs and application error traces are automatically purged after 30 to 90 days.
  • Sanitization Standards: Storage volume decommissioning follows cryptographic deletion or zero-fill overwriting routines matching NIST SP 800-88 guidelines.

7. AI & Machine Learning Data Governance

Enterprise AI Privacy Guarantee

When delivering AI solutions, custom agent workflows, or Retrieval-Augmented Generation (RAG) pipelines for clients:

  • No Foundation Model Training: We use enterprise API endpoints (e.g. Google Vertex AI / Gemini API, OpenAI Enterprise) governed by zero-retention data privacy terms. Client inputs, prompts, code bases, and documents are never used to train public AI models.
  • Isolated Vector Databases: Vector embeddings generated for client document search are stored in isolated, access-controlled vector stores (e.g. PGVector, Pinecone, or client-hosted vector databases) encrypted at rest.

8. Incident Response & Vulnerability Handling

We maintain an Incident Response Protocol to ensure rapid identification, containment, and transparent communication if a security event occurs.

Continuous Monitoring

Automated log aggregation, intrusion detection alerts, and vulnerability scanning on key software dependencies.

Client Notification Commitment

In the event of a verified security breach impacting client data, AVS will notify affected client administrators without unreasonable delay (typically within 48 to 72 hours of confirmation) with detailed remediation details.

9. Third-Party Infrastructure & Subprocessors

To provide robust engineering and cloud infrastructure, AVS utilizes carefully evaluated third-party service providers. Each subprocessor is vetted for data protection compliance:

SubprocessorPurposeLocation
Vercel Inc.Frontend application hosting & Edge CDN (optional cloud hosting provider)Global / USA
Amazon Web Services (AWS)Cloud infrastructure, relational databases, S3 storage bucketsGlobal (Client-selected region)
Google Cloud Platform (GCP) / Vertex AIEnterprise AI API model inference, cloud analytics pipelinesGlobal (EU / US)
Supabase Inc.Managed PostgreSQL databases & backend servicesGlobal (EU / US)
Meta / WhatsApp Business APIMessaging API infrastructure for automated customer messagingGlobal / USA

Security & Compliance Inquiry

Need a custom Data Processing Agreement (DPA), security questionnaire completion, or vulnerability report? We are ready to assist your compliance team.

Contact Security Team