AUVYTrust Center

Trust you can review

EU-hosted workspaces, public processor disclosures, and the contracts buyers need — written for security, legal, and procurement review.

  • Core EU hosting
  • Public AVV / DPA
  • Processor register
  • AI transparency

Controls

Practical controls for access, encryption, isolation, connected tools, logging, continuity, and privacy.

How AUVY protects your workspace. These practices follow our published data processing agreement. SOC 2 Type II and ISO 27001 certification are in progress and are not claimed here.

Last reviewed: 2026-08-03

Governance

  • Named security and privacy contacts
  • Public channels for security incidents and privacy requests
  • Live subprocessor list with notice before material changes
  • Limited production access for AUVY staff

Identity and access

  • Workspace roles control what each person can see and do
  • Sign-in with password, magic link, or organisation SSO where enabled
  • Access always follows the signed-in user
  • Owners can export or delete workspace data; those actions are logged

Infrastructure and encryption

  • Core workspace and account hosting in the EU (Helsinki)
  • Encryption in transit (TLS 1.2 or higher)
  • Encryption at rest for production data
  • Extra protection for documents and connected-account secrets
  • Physical security via EU data centres of approved subprocessors

Product security

  • Logical separation between customer workspaces
  • Authenticated product APIs
  • Reviewed changes and controlled releases
  • Hardened hosts and ongoing patching

Integrations

  • Connected tools run only inside the workspace that enabled them
  • Credentials for connected tools are stored encrypted
  • Services you connect remain under your control
  • Optional analytics run only when you turn them on

Logging and incidents

  • Activity log for security-relevant actions, including export and deletion (about 12 months)
  • Monitoring of service health
  • Personal-data breach duties under GDPR
  • Report security issues to security@auvy.ai

Availability

  • Daily encrypted backups of primary workspace content
  • Separate backup practices for account data
  • Documented restore procedures and continuous monitoring

Privacy and AI

  • Published processor list with regions, optional paths, and contract or privacy sources
  • In-product export and owner-authorized workspace deletion with logging
  • Contractual deletion timelines after the contract ends
  • AUVY does not use customer data to train AI models
  • Only the context for the current AI request is sent to the selected model
  • Default web search uses Linkup (EU)
  • Article 50 AI interaction and role-specific transparency disclosures
  • Machine-readable provenance is use-case dependent and can degrade downstream
  • Privacy requests: privacy@auvy.ai

At a glance

AreaSummary
IsolationEach workspace belongs to one organisation. Access follows who is signed in.
EncryptionTLS in transit, encryption at rest, and extra protection for documents and secrets.
AccessWorkspace roles, signed-in access, and limited AUVY staff access.
LoggingSecurity-relevant actions — including export and delete — are recorded.
AvailabilityDaily encrypted backups, documented restores, and active monitoring.
IntegrationsConnected tools stay inside your workspace; secrets are encrypted.
Privacy & AIProcessors and optional paths are published. AUVY does not train on customer data. AI duties and locations depend on role, feature, and provider.
AssuranceSOC 2 Type II and ISO 27001 are in progress. Current status is on Compliance.

Learn more