Controls
The security and privacy measures AUVY runs today, grouped by area. Each one names the document where it is written down.
These are the technical and organisational measures from the AVV (Annex 2) as AUVY runs them today. This is not an audit report or a certification. Read Annex 2 in the DPA.
Infrastructure security
Where the service runs and how it is kept available.
- AVV Annex 2 · A
Data stored in Helsinki
All customer data, including accounts and sessions, is stored in Hetzner data centres in Helsinki.
- AVV Annex 2 · C
Encrypted backups
The document, account and vector stores are backed up (daily and weekly), encrypted with AES-256-GCM and kept for 30 days in Helsinki.
- AVV Annex 2 · C
Monitoring and alerting
The service, including its queues and workers, is monitored and raises alerts.
- AVV Annex 2 · C
Recovery processes
Data can be restored from the encrypted backups.
- AVV Annex 2 · B
Patching and hardening
Servers get security updates promptly and run hardened configurations.
Data security
How customer data is protected in transit and in backups.
- AVV Annex 2 · A
Encryption in transit
TLS 1.2 or higher for connections to AUVY and between AUVY and its providers.
- Data handling
Protected secrets and documents
Document contents and connected-account secrets receive additional protection.
- AVV Annex 2 · E
No model training on customer data
AUVY does not use or designate customer data for model training.
- AVV § 11
Export and deletion
Workspace content can be exported at any time and is deleted within 30 days after the contract ends (AVV § 11).
Access control
Who can reach a workspace, and how that is enforced.
- AVV Annex 2 · A
Logical workspace isolation
Each workspace belongs to one organisation; workspace scope is bound on the server.
- AVV Annex 2 · A
Role-based access
Access follows workspace roles, with least privilege for signed-in members.
- AVV Annex 2 · A
Multi-factor authentication
MFA and WebAuthn passkeys are supported where enabled for the account.
- Data handling
Limited staff access
AUVY staff have limited production access for support and operations only.
- Data handling
Logged exports and deletions
Security-relevant actions, exports and deletions are written to the workspace activity log (kept about 12 months).
Product security
How changes reach production safely.
- AVV Annex 2 · B
Code review
Changes are reviewed before they are merged.
- AVV Annex 2 · B
Controlled deployments
Only reviewed changes are deployed to production.
- AVV Annex 2 · B
Authenticated APIs
APIs require authentication, and the server holds authority over workspace scope.
- AVV Annex 2 · D
Tenant-isolation testing and security reviews
Workspace isolation is tested, and the code gets security reviews.
Incident response
How security events are detected, handled and reported.
- AVV Annex 2 · D
Security and audit logging
Sign-ins, failed attempts and administrative actions are logged centrally.
- AVV Annex 2 · D
Documented incident response
A documented process covers handling incidents and notifying customers.
- AVV § 8
Breach notification
Customers are notified within 24 hours after AUVY becomes aware of a personal data breach (AVV § 8).
- Vulnerability Disclosure Policy
Vulnerability disclosure
A public policy explains how to report vulnerabilities to security@auvy.ai; complete reports are acknowledged within about five business days.
Privacy
GDPR documentation and customer rights.
- AVV
Art. 28 GDPR agreement
A standard AVV is published; the German text is binding, with an English translation.
- AVV § 6 · Annex 3
Public subprocessor register
AUVY-selected processors are listed with purpose, data categories and location; changes are announced at least 30 days in advance.
- AVV Annex 2 · E
First-party product analytics
Product analytics runs on AUVY-operated infrastructure. No third-party analytics provider is used.
- AVV § 9
Audit rights
Customers or an independent auditor may audit once a year, with at least 20 business days’ notice.
- AVV Annex 2 · F
Data-subject request support
AUVY helps with data subject requests and data protection impact assessments.
- AVV § 12
Professional secrecy (§ 203 StGB)
Available for Enterprise once activated in writing under the AVV.