Practical controls for access, encryption, isolation, connected tools, logging, continuity, and privacy.
How AUVY protects your workspace. These practices follow our published data processing agreement. SOC 2 Type II and ISO 27001 certification are in progress and are not claimed here.
Last reviewed: 2026-08-03
Governance
Named security and privacy contacts
Public channels for security incidents and privacy requests
Live subprocessor list with notice before material changes
Limited production access for AUVY staff
Identity and access
Workspace roles control what each person can see and do
Sign-in with password, magic link, or organisation SSO where enabled
Access always follows the signed-in user
Owners can export or delete workspace data; those actions are logged
Infrastructure and encryption
Core workspace and account hosting in the EU (Helsinki)
Encryption in transit (TLS 1.2 or higher)
Encryption at rest for production data
Extra protection for documents and connected-account secrets
Physical security via EU data centres of approved subprocessors
Product security
Logical separation between customer workspaces
Authenticated product APIs
Reviewed changes and controlled releases
Hardened hosts and ongoing patching
Integrations
Connected tools run only inside the workspace that enabled them
Credentials for connected tools are stored encrypted
Services you connect remain under your control
Optional analytics run only when you turn them on
Logging and incidents
Activity log for security-relevant actions, including export and deletion (about 12 months)
Monitoring of service health
Personal-data breach duties under GDPR
Report security issues to security@auvy.ai
Availability
Daily encrypted backups of primary workspace content
Separate backup practices for account data
Documented restore procedures and continuous monitoring
Privacy and AI
Published processor list with regions, optional paths, and contract or privacy sources
In-product export and owner-authorized workspace deletion with logging
Contractual deletion timelines after the contract ends
AUVY does not use customer data to train AI models
Only the context for the current AI request is sent to the selected model
Default web search uses Linkup (EU)
Article 50 AI interaction and role-specific transparency disclosures
Machine-readable provenance is use-case dependent and can degrade downstream
Privacy requests: privacy@auvy.ai
At a glance
Area
Summary
Isolation
Each workspace belongs to one organisation. Access follows who is signed in.
Encryption
TLS in transit, encryption at rest, and extra protection for documents and secrets.
Access
Workspace roles, signed-in access, and limited AUVY staff access.
Logging
Security-relevant actions — including export and delete — are recorded.
Availability
Daily encrypted backups, documented restores, and active monitoring.
Integrations
Connected tools stay inside your workspace; secrets are encrypted.
Privacy & AI
Processors and optional paths are published. AUVY does not train on customer data. AI duties and locations depend on role, feature, and provider.
Assurance
SOC 2 Type II and ISO 27001 are in progress. Current status is on Compliance.