Security
Published by: AvanceAI LLC
Version: 2026-07-26.1
Last updated: July 26, 2026
Summary of security practices at AvanceAI LLC for AVA by Avance (avance.ai / app.avance.ai). We describe only controls we can assert based on current operations. We make no certification claims (for example SOC 2, ISO 27001, PCI DSS, or HIPAA).
Infrastructure
- Production on Amazon Web Services, region
us-east-1(United States). - Personal data of Colombian data subjects is processed on that U.S. infrastructure (international transfer). We do not operate AVA production infrastructure in Colombia.
Encryption and backups
- In transit: application and API traffic protected with TLS.
- At rest: the managed database (RDS) uses encryption at rest.
- Backups: automated RDS backups with a 30-day retention period.
Administrative access
- Human access to the AWS account uses MFA (including MFA-protected break-glass access).
- CI/CD deploy automation uses OIDC (GitHub Actions federated roles) instead of long-lived keys where that flow is configured.
- Product access control is role-based (RBAC).
Logging and isolation
- CloudTrail for auditing privileged activity in AWS.
- Logical tenant isolation in the product data model and authorization so authenticated users operate within their account/location scope.
Responsible disclosure
If you believe you have found a security vulnerability, email security@avance.ai with a clear description, reproduction steps when possible, and your contact channel. Do not seek or offer unauthorized access to third-party data. We aim to acknowledge reports and follow up in good faith.
For privacy or general support: privacy@avance.ai · support@avance.ai.