Security

Published by: AvanceAI LLC
Version: 2026-07-26.1
Last updated: July 26, 2026

Summary of security practices at AvanceAI LLC for AVA by Avance (avance.ai / app.avance.ai). We describe only controls we can assert based on current operations. We make no certification claims (for example SOC 2, ISO 27001, PCI DSS, or HIPAA).

Infrastructure

  • Production on Amazon Web Services, region us-east-1 (United States).
  • Personal data of Colombian data subjects is processed on that U.S. infrastructure (international transfer). We do not operate AVA production infrastructure in Colombia.

Encryption and backups

  • In transit: application and API traffic protected with TLS.
  • At rest: the managed database (RDS) uses encryption at rest.
  • Backups: automated RDS backups with a 30-day retention period.

Administrative access

  • Human access to the AWS account uses MFA (including MFA-protected break-glass access).
  • CI/CD deploy automation uses OIDC (GitHub Actions federated roles) instead of long-lived keys where that flow is configured.
  • Product access control is role-based (RBAC).

Logging and isolation

  • CloudTrail for auditing privileged activity in AWS.
  • Logical tenant isolation in the product data model and authorization so authenticated users operate within their account/location scope.

Responsible disclosure

If you believe you have found a security vulnerability, email security@avance.ai with a clear description, reproduction steps when possible, and your contact channel. Do not seek or offer unauthorized access to third-party data. We aim to acknowledge reports and follow up in good faith.

For privacy or general support: privacy@avance.ai · support@avance.ai.