Data Protection & Security Statement
Transparent details on how we safeguard client data, maintain operational integrity, and enforce strict security controls across custom software, AI, cloud, data engineering, analytics, and security engagements.
Our Security Standard & Philosophy
We apply industry-standard security practices including encrypted communication, access controls, secure authentication, and regular backups.
As an engineering agency delivering custom software, AI integrations, data pipelines, cloud solutions, analytics platforms, and security advisory, we believe transparency is paramount. We do not make exaggerated or impossible security claims—such as claiming any system is "100% unhackable" or "flawless." Instead, we build multi-layered security controls into every stage of the software development lifecycle (SDLC) and infrastructure deployment.
1. Where Customer Data is Stored
Customer data location depends on the architecture selected for your specific project (cloud SaaS, client-hosted infrastructure, or hybrid deployment). By default, our client solutions leverage tier-1 cloud providers equipped with physical security controls, ISO 27001, SOC 2 Type II, and PCI-DSS compliance certifications.
Managed Cloud Infrastructure
Web applications and edge endpoints are hosted on high-availability global cloud platforms (such as Vercel, AWS, or GCP). Application servers are deployed within isolated Virtual Private Clouds (VPC) or container environments.
Data Residency & Databases
Structured databases (e.g. PostgreSQL, Supabase, MySQL) and object storage buckets are provisioned in client-specified geographical regions (e.g. EU, US, or South Africa data centers) to satisfy local regulatory requirements.
2. Who Can Access Customer Data
We strictly restrict human access to production databases and client project repositories following the Principle of Least Privilege (PoLP).
- Role-Based Access Control (RBAC): Only engineers explicitly assigned to a client engagement receive access permissions required for support, maintenance, or debugging.
- Confidentiality Obligations: All AVS engineers and consultants sign strict Non-Disclosure Agreements (NDAs) and undergo security policy training prior to onboard handling of code or client databases.
- Zero Data Monetization: We never sell, lease, rent, or trade client data, source code, or proprietary datasets to third parties under any circumstances.
3. Backups & Disaster Recovery
To guard against hardware failure, corruption, or unintentional loss, automated backup workflows are configured for all production databases managed by AVS.
Automated Snapshots
Daily automated snapshots with Point-in-Time Recovery (PITR) enabled for transactional databases.
Redundant Storage
Backups are stored in geographically separated object storage designed for 99.999999999% (11 9s) durability.
Restoration Tests
Periodic restoration validation drills to ensure Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are met.
4. Authentication & Credentials
Security begins with robust access verification across internal developer accounts and application user management systems:
Internal Engineering Security
Mandatory Multi-Factor Authentication (MFA) via hardware security keys or authenticator apps across all developer accounts, code repositories, cloud consoles, and secrets vaults. Password reuse is strictly forbidden.
Application Security Built for Clients
When engineering user authentication systems for clients, we implement industry-standard identity protocols—including OAuth 2.0 / OpenID Connect, JWT tokens with short time-to-live (TTL), secure password hashing (Argon2 or bcrypt), rate-limiting against brute force attacks, and HTTP-only CSRF-protected cookies.
5. Encryption Standards (In Transit & At Rest)
All data moving across networks or stored on disk is protected using strong cryptographic algorithms.
Encryption in Transit
All network communication, Web APIs, and client-server traffic mandate Transport Layer Security (TLS 1.2 or TLS 1.3) with modern cipher suites. Plain HTTP requests are automatically redirected to HTTPS with HSTS headers enforced.
Encryption at Rest
Database volumes, file attachments, and snapshot backups are encrypted at rest using AES-256 (Advanced Encryption Standard). API keys and secrets are securely stored in KMS vaults or encrypted environment variables.
6. Data Retention & Secure Disposal
We retain customer project data and telemetry only as long as necessary to fulfill contractual obligations, provide active support, or maintain compliance with legal requirements.
- Active Engagements: Operational data is stored for the lifecycle of the active client agreement.
- Post-Termination Deletion: Upon completion or termination of a contract, client data hosted in AVS-controlled staging environments is deleted within 30 days upon client written request.
- System Logs: Operational access logs and application error traces are automatically purged after 30 to 90 days.
- Sanitization Standards: Storage volume decommissioning follows cryptographic deletion or zero-fill overwriting routines matching NIST SP 800-88 guidelines.
7. AI & Machine Learning Data Governance
Enterprise AI Privacy Guarantee
When delivering AI solutions, custom agent workflows, or Retrieval-Augmented Generation (RAG) pipelines for clients:
- •No Foundation Model Training: We use enterprise API endpoints (e.g. Google Vertex AI / Gemini API, OpenAI Enterprise) governed by zero-retention data privacy terms. Client inputs, prompts, code bases, and documents are never used to train public AI models.
- •Isolated Vector Databases: Vector embeddings generated for client document search are stored in isolated, access-controlled vector stores (e.g. PGVector, Pinecone, or client-hosted vector databases) encrypted at rest.
8. Incident Response & Vulnerability Handling
We maintain an Incident Response Protocol to ensure rapid identification, containment, and transparent communication if a security event occurs.
Continuous Monitoring
Automated log aggregation, intrusion detection alerts, and vulnerability scanning on key software dependencies.
Client Notification Commitment
In the event of a verified security breach impacting client data, AVS will notify affected client administrators without unreasonable delay (typically within 48 to 72 hours of confirmation) with detailed remediation details.
9. Third-Party Infrastructure & Subprocessors
To provide robust engineering and cloud infrastructure, AVS utilizes carefully evaluated third-party service providers. Each subprocessor is vetted for data protection compliance:
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Frontend application hosting & Edge CDN (optional cloud hosting provider) | Global / USA |
| Amazon Web Services (AWS) | Cloud infrastructure, relational databases, S3 storage buckets | Global (Client-selected region) |
| Google Cloud Platform (GCP) / Vertex AI | Enterprise AI API model inference, cloud analytics pipelines | Global (EU / US) |
| Supabase Inc. | Managed PostgreSQL databases & backend services | Global (EU / US) |
| Meta / WhatsApp Business API | Messaging API infrastructure for automated customer messaging | Global / USA |
Security & Compliance Inquiry
Need a custom Data Processing Agreement (DPA), security questionnaire completion, or vulnerability report? We are ready to assist your compliance team.
