Our Approach
Aventro handles sensitive company and diligence information, including material non-public information. We design the Service to protect it using layered technical and organizational controls.
Data Protection
- Encryption in transit: traffic is encrypted using TLS.
- Encryption at rest for sensitive evidence: sensitive evidence categories (for example financials, cap tables, and IP) are encrypted at rest using per-Deal derived keys.
- Private storage: evidence files are stored in access-controlled, non-public storage; access is scoped to authorized users.
Access Control
- Role-based access and row-level security enforce who can see each Deal and Organization's data.
- Organization-level segregation: data from one organization is not accessible to another.
- Least-privilege operations: administrative access is restricted to named personnel, and privileged actions that modify customer data are logged.
Monitoring and Auditability
- Security-relevant actions (visibility changes, shares, exports) are logged.
- We use error monitoring to detect and resolve issues.
AI and Data Handling
- We do not use one customer's Content to train models for another customer, and we do not authorize our AI providers to use your Content to train their general-purpose models.
- Optional product analytics run only with your consent. We do not record sessions, and automatic event capture is disabled — only explicit, minimized events are collected.
Infrastructure
- We build on established cloud providers that maintain independent security certifications (for example SOC 2 and/or ISO 27001). These certifications belong to our providers; Aventro Ltd. does not represent that it holds them itself unless separately stated.
Resilience and Recovery
- Backups: the production database and stored files are backed up on a daily schedule. Backups run on automated infrastructure and do not depend on a person initiating them. Each backup is encrypted before it leaves the platform, and is held with a separate provider in the European Union, under access control separate from the production platform and under a key that provider does not hold.
- Scope: backups cover the application database together with stored evidence and generated report files.
- Restoration: we maintain a documented restoration procedure, and we exercise it against the off-platform copy rather than only against a local one. Restored data is checked against a record of row counts and file digests captured at the time the backup was taken, so an incomplete restore is detected rather than assumed successful. The most recent restoration test was completed on 28 July 2026.
- Encrypted evidence: evidence encrypted with per-Deal derived keys is restored in encrypted form and requires the corresponding key material to be read.
Reporting a Vulnerability
If you believe you have found a security issue, contact security@aventro.ai. Please give us a reasonable opportunity to investigate and remediate before public disclosure.
Questions about this document? Contact us at legal@aventro.ai