Trust

Security at Avanis AI

Last updated: July 2026

Institutional teams hand us the workflows their decisions run on. This page describes plainly how we handle data, both on this website and inside client engagements, and what is on our compliance roadmap. Questions or security questionnaires: Avanis.AI@outlook.com (we complete questionnaires under NDA).

1. Two different scopes

This website is a marketing site: it collects only what you type into its forms and anonymous, cookie-less usage analytics. Client engagements are governed separately, by contract and NDA, and typically involve far stricter controls described below. Nothing you browse here requires an account, and we set no tracking cookies.

2. Data this website handles

Contact and newsletter forms collect the name, email, and message you submit. Submissions are relayed over HTTPS by our form processor directly to our email; we do not operate a database of visitor submissions. Analytics are aggregate and anonymous (pages viewed, country, device class) and cannot identify you individually.

3. Client engagements: where your data lives

Deployment is the client's choice: fully on-premises, the client's private cloud, or a managed environment. For local-first builds, documents, models, and outputs never leave the client's network. We work NDA-first, and client data is never used to train public or shared models, ours or anyone else's.

4. Encryption

All traffic to this website and to hosted deployments is encrypted in transit with TLS 1.2 or higher. Data at rest on our hosting and code infrastructure is encrypted by the underlying providers (see sub-processors below). For client deployments, encryption standards follow the client's infrastructure requirements and are agreed before any data moves.

5. Access control

Source code lives in private repositories with two-factor authentication enforced. Access follows least privilege; today Avanis AI is deliberately small, which means the access list is short and auditable. Client environments are accessed only with named, client-granted credentials, never shared accounts.

6. Sub-processors (this website)

Vercel (site hosting and anonymous analytics), GitHub (private code hosting), and FormSubmit (relay of form submissions to our email). Client engagements use a sub-processor list agreed per contract; for local-first deployments the list can be zero.

7. Retention and deletion

Form submissions are retained as ordinary business correspondence. You may request deletion of your personal data at any time by emailing Avanis.AI@outlook.com; we action requests within 30 days. Engagement data retention is defined by contract, with return-or-destroy terms at engagement end.

8. Compliance roadmap

We are honest about where we are: Avanis AI is an early-stage company and does not yet hold a SOC 2 attestation. SOC 2 readiness is on our near-term roadmap as client engagements formalize, and our engineering practices, private infrastructure, least-privilege access, audit trails in the product, are built so that certification is a documentation exercise, not a re-architecture. In the meantime we support client due diligence directly: questionnaires, architecture walkthroughs, and data-flow diagrams under NDA.

9. Reporting a vulnerability

If you believe you have found a security issue on this website or in our software, email Avanis.AI@outlook.com with the details. We acknowledge reports within 48 hours and will not pursue good-faith researchers.