Skip to content

Controls

The security and privacy measures AUVY runs today, grouped by area. Each one names the document where it is written down.

28 controls, as of 10 Aug 2026

These are the technical and organisational measures from the AVV (Annex 2) as AUVY runs them today. This is not an audit report or a certification. Read Annex 2 in the DPA.

Infrastructure security

Where the service runs and how it is kept available.

  • Data stored in Helsinki

    All customer data, including accounts and sessions, is stored in Hetzner data centres in Helsinki.

    AVV Annex 2 · A
  • Encrypted backups

    The document, account and vector stores are backed up (daily and weekly), encrypted with AES-256-GCM and kept for 30 days in Helsinki.

    AVV Annex 2 · C
  • Monitoring and alerting

    The service, including its queues and workers, is monitored and raises alerts.

    AVV Annex 2 · C
  • Recovery processes

    Data can be restored from the encrypted backups.

    AVV Annex 2 · C
  • Patching and hardening

    Servers get security updates promptly and run hardened configurations.

    AVV Annex 2 · B

Data security

How customer data is protected in transit and in backups.

  • Encryption in transit

    TLS 1.2 or higher for connections to AUVY and between AUVY and its providers.

    AVV Annex 2 · A
  • Protected secrets and documents

    Document contents and connected-account secrets receive additional protection.

    Data handling
  • No model training on customer data

    AUVY does not use or designate customer data for model training.

    AVV Annex 2 · E
  • Export and deletion

    Workspace content can be exported at any time and is deleted within 30 days after the contract ends (AVV § 11).

    AVV § 11

Access control

Who can reach a workspace, and how that is enforced.

  • Logical workspace isolation

    Each workspace belongs to one organisation; workspace scope is bound on the server.

    AVV Annex 2 · A
  • Role-based access

    Access follows workspace roles, with least privilege for signed-in members.

    AVV Annex 2 · A
  • Multi-factor authentication

    MFA and WebAuthn passkeys are supported where enabled for the account.

    AVV Annex 2 · A
  • Limited staff access

    AUVY staff have limited production access for support and operations only.

    Data handling
  • Logged exports and deletions

    Security-relevant actions, exports and deletions are written to the workspace activity log (kept about 12 months).

    Data handling

Product security

How changes reach production safely.

  • Code review

    Changes are reviewed before they are merged.

    AVV Annex 2 · B
  • Controlled deployments

    Only reviewed changes are deployed to production.

    AVV Annex 2 · B
  • Authenticated APIs

    APIs require authentication, and the server holds authority over workspace scope.

    AVV Annex 2 · B
  • Tenant-isolation testing and security reviews

    Workspace isolation is tested, and the code gets security reviews.

    AVV Annex 2 · D

Incident response

How security events are detected, handled and reported.

  • Security and audit logging

    Sign-ins, failed attempts and administrative actions are logged centrally.

    AVV Annex 2 · D
  • Documented incident response

    A documented process covers handling incidents and notifying customers.

    AVV Annex 2 · D
  • Breach notification

    Customers are notified within 24 hours after AUVY becomes aware of a personal data breach (AVV § 8).

    AVV § 8
  • Vulnerability disclosure

    A public policy explains how to report vulnerabilities to security@auvy.ai; complete reports are acknowledged within about five business days.

    Vulnerability Disclosure Policy

Privacy

GDPR documentation and customer rights.

  • Art. 28 GDPR agreement

    A standard AVV is published; the German text is binding, with an English translation.

    AVV
  • Public subprocessor register

    AUVY-selected processors are listed with purpose, data categories and location; changes are announced at least 30 days in advance.

    AVV § 6 · Annex 3
  • First-party product analytics

    Product analytics runs on AUVY-operated infrastructure. No third-party analytics provider is used.

    AVV Annex 2 · E
  • Audit rights

    Customers or an independent auditor may audit once a year, with at least 20 business days’ notice.

    AVV § 9
  • Data-subject request support

    AUVY helps with data subject requests and data protection impact assessments.

    AVV Annex 2 · F
  • Professional secrecy (§ 203 StGB)

    Available for Enterprise once activated in writing under the AVV.

    AVV § 12