TRUST CENTRE

Where the controls live.

Everything your security, legal, or procurement team usually asks for, on one page: the standards we hold ourselves to, the companies we work with to run the service, where your data lives, how to sign a data-protection agreement, and how to report a vulnerability. Honest and straight to the point.

Request a DPA or security reviewRead the security stack →
FRAMEWORKS WE ALIGN TO

We don’t hold certifications today. Here’s what we do.

Avrentis has not yet completed a SOC 2 or ISO 27001 audit. The platform is built with the controls those frameworks measure and we’re transparent about where we are in each journey.

SOC 2 (Type II)

Controls aligned · audit not yet completed

The way we handle access, change management, security, uptime, and incident response is designed to meet SOC 2 Type II standards. We can walk your team through each of those areas on a review call.

ISO 27001

Controls aligned · certification not in place

The way we run information security follows the areas ISO 27001 cares about — who can access what, how we protect assets, how we encrypt things, how we run operations, and how we manage the suppliers we use.

GDPR & UK GDPR

Designed-for · DPA available

The rights your users have under GDPR — to see their data, correct it, delete it, and take it with them — are all supported directly in the product. A Data Processing Agreement is available to sign on request.

NDPR (Nigeria)

Designed-for

The way the platform handles personal data follows what Nigeria's data protection regulation asks for — lawful reason for collecting it, keeping only what's needed, protecting it, and responding quickly if something goes wrong.

CCPA / CPRA

Designed-for

If you operate in California, your customers' rights to know what you hold about them, delete it, and opt out of sale are supported. Avrentis does not sell personal data — full stop.

SUB-PROCESSORS

The providers that help us run the service.

Each provider has a data-processing agreement in place with Avrentis. We notify customers of new sub-processors before onboarding them where we have that obligation under your contract.

CategoryRegionDPA
Managed PostgreSQL for application dataEUSIGNED
Application hosting and edge computeGlobal edgeSIGNED
CDN and object storage for document attachmentsGlobalSIGNED
Managed Redis for sessions and rate-limitingEU / USSIGNED
Transactional email deliveryUSSIGNED
SMS notification delivery (where enabled)Africa / internationalSIGNED
Error and performance monitoringEUSIGNED
Need the named vendor list?
The specific providers in each category — with their DPA status and any changes — are shared with prospective customers on request, typically alongside a Data Processing Agreement.
Request the list

Subscribe to sub-processor change notifications through our update subscription form.

DOCUMENTS & DIRECT LINES

What to read and who to email.

Security overview

The full stack — tenant isolation, RBAC + ABAC, session integrity, audit, encryption.

Read the stack

Data Processing Agreement

GDPR + UK GDPR-aligned DPA with standard contractual clauses. Signable as-is or negotiated for enterprise.

Request the DPA

Privacy policy

What we collect, why, how long we keep it, and your rights as a data subject.

Read the policy

Terms of service

Service description, acceptable use, data ownership, liability, termination.

Read the terms

Responsible disclosure

Report security issues to security@avrentis.com. We triage within two business days.

Report a vulnerability

Data residency

Primary data in the EU today. In-country/in-region hosting available as an enterprise engagement.

Talk to us about residency
DATA RESIDENCY

Where your data lives — today and on the roadmap.

Residency matters for regulated organisations and for customers whose policies require data to stay in a specific jurisdiction. Here is the honest picture.

Today · default

European Union

Primary application data and its backups are hosted in the EU. Document attachments flow through an encrypted object-storage provider at the region configured for our infrastructure tier. The marketing site and edge compute run on a global edge network.

Enterprise · on request

In-region / in-country hosting

We can provision a dedicated infrastructure tier in another region as part of an enterprise engagement — useful when your policy, regulator, or customer contract mandates data remain in a specific jurisdiction.

Roadmap

Multi-region failover

Active-passive replication across regions with Customer-selectable primary and documented RPO/RTO. In scoping now; enterprise partners are helping us shape the requirements.

Cross-border transfers. Where personal data moves between regions, we rely on Standard Contractual Clauses (SCCs) and equivalent mechanisms recognised under applicable law. Our DPA sets out these terms in full.
OPERATIONAL TRANSPARENCY

All systems operational.

Current subsystem status is published on the status page, with incident history as it accrues. Enterprise customers receive incident notifications under their order form; email to be added to the general notification list.

Open the status pageTalk to our team →