Skip to main content
Legal

Security Overview

Last updated: 2026-08-25

·

Security inquiries: contact@avyonintelligence.com

A public summary of Avyon Intelligence security posture, controls, and enterprise trust materials.

Security posture overview

This page describes the security controls Avyon has actually built, and names the ones it has not. Avyon is a young company: several controls a mature vendor would list here are targets rather than attainments, and they are marked as such below rather than omitted. If you are assessing Avyon for an engagement, send your security questions or your own questionnaire to contact@avyonintelligence.com and we will answer them directly.

Access control

Avyon systems implement role-based access control, and tenant isolation is enforced at the database with row-level security rather than in application code alone. Multi-factor authentication is available and enforced for administrative access: TOTP, through Google Identity Platform. SMS-based MFA is prohibited for all user types. Hardware security keys (FIDO2) are a target, not an attainment — no FIDO2 enrolment exists today, and administrators use TOTP. Periodic access recertification is built into the platform; a quarterly review cadence is the intent, and we do not claim a completed cycle.

Data encryption

Data in transit is encrypted in accordance with the platform defaults of Google Cloud and Cloudflare. Data at rest is encrypted by Google Cloud SQL, which applies AES-256 by default. Secrets are held in Google Secret Manager rather than in configuration or source. A 90-day rotation period for database passwords and third-party API keys is documented in our security model — the automated rotation mechanism is not built yet, and the document says so. Application-level column encryption of individual sensitive fields is specified as a target and is not implemented today.

Infrastructure security

Avyon infrastructure runs on Google Cloud Platform and is managed as code with Terraform, so a change to the production environment is reviewable in version control. Cloudflare provides DNS and content delivery. There is one deployed environment: production. Separate staging and development environments are planned and do not exist yet, so we do not claim segmentation between them.

Vulnerability management

Our CI pipeline runs dependency and secret scanning on every push, alongside build, lint, test, a live row-level-security check against a real database, and infrastructure validation. Container images are scanned before deployment, and a critical finding blocks the release. Static application security testing (SAST) is not yet part of the pipeline. Independent third-party penetration testing has not been carried out. Security findings and enterprise risks are recorded in the platform's own governance register.

Incident response

Incidents are recorded in the platform with a severity classification and a containment target: P0 one hour, P1 four hours, P2 twenty-four hours, P3 five business days. Incident state, containment time and post-incident review are tracked against those targets. Clients are notified of incidents affecting their data as required by applicable law and by the terms of the engagement. A formal executive notification SLA is not yet defined.

Compliance certifications

Avyon holds no third-party security certifications at this time. ISO 27001:2022 and SOC 2 Type II are targets, not attainments, and neither has been audited. Our controls are designed against those frameworks, and GDPR and DPDPA 2023 obligations are self-assessed and documented. We will publish certification status here when it changes; for our current control documentation, contact@avyonintelligence.com.