AUVYTrust Center

Trust you can review

EU-hosted workspaces, public processor disclosures, and the contracts buyers need — written for security, legal, and procurement review.

  • Core EU hosting
  • Public AVV / DPA
  • Processor register
  • AI transparency

Core EU hosting, role-specific privacy and AI disclosures, and how we keep each workspace separate. Formal SOC 2 and ISO 27001 certification are in progress.

Compliance

View all

§203

GDPR documentation

Core EU hosting

SOC 2 Type II (in progress)

ISO 27001 (in progress)

Controls

Last reviewed: 2026-08-03

View all

Governance

  • Named security and privacy contacts
  • Public channels for security incidents and privacy requests
  • Live subprocessor list with notice before material changes
  • Limited production access for AUVY staff

Identity and access

  • Workspace roles control what each person can see and do
  • Sign-in with password, magic link, or organisation SSO where enabled
  • Access always follows the signed-in user
  • Owners can export or delete workspace data; those actions are logged

Infrastructure and encryption

  • Core workspace and account hosting in the EU (Helsinki)
  • Encryption in transit (TLS 1.2 or higher)
  • Encryption at rest for production data
  • Extra protection for documents and connected-account secrets
  • Physical security via EU data centres of approved subprocessors

Product security

  • Logical separation between customer workspaces
  • Authenticated product APIs
  • Reviewed changes and controlled releases
  • Hardened hosts and ongoing patching