1. Our Approach to Security
Avertis is designed for industrial maintenance environments where operational data, asset history and engineering knowledge can be commercially sensitive. Security is treated as a core platform requirement.
Draft for review. This page describes current and target practices in good faith; roadmap items should not be represented as completed certifications.
Avertis is designed for industrial maintenance environments where operational data, asset history and engineering knowledge can be commercially sensitive. Security is treated as a core platform requirement.
Customer data is protected using cloud security controls and encryption appropriate to the service. Access to production systems and customer data is limited to authorised personnel with a legitimate operational need.
Avertis applies role-based access principles across the platform. Administrative and privileged access is restricted and controls are reviewed as the platform grows.
Avertis uses managed cloud infrastructure and separates application, data and supporting services through the controls provided by those platforms.
Secure development practices include input validation, dependency monitoring and code review prior to release. Independent penetration testing forms part of the security roadmap.
Avertis uses regular backups, with backup data encrypted and stored separately from production systems. Formal recovery objectives are being developed.
Avertis will work to contain, investigate and remediate incidents affecting customer data and notify affected customers in line with applicable obligations.
Avertis is not currently claiming ISO 27001, SOC 2 or equivalent certification. Formal certification forms part of the longer-term security roadmap.
If you believe you have identified a security issue affecting Avertis, contact security@avertis.ai with enough information for the team to investigate.