AEVIONTrust · IP · Globus
DemoExploreShopAuthQRightQSignBureauPlanetAwardsBankChessPricingAPI
All plans
SECURITY & COMPLIANCE

Security & Compliance

AEVION was built with enterprise-grade security from day one. Customer data lives in isolated namespaces, encrypted with AES-256 at rest and TLS 1.3 in transit. We undergo independent SOC 2 Type II audits, meet GDPR, 152-FZ, and PCI DSS requirements, and publish our security policies openly.

Certifications & compliance

SOC 2 Type II
Certified
Security, Availability, Confidentiality
GDPR
Compliant
EU General Data Protection Regulation
152-ФЗ
Compliant
Federal Law on Personal Data (Russia)
PCI DSS
Level 1
Payment Card Industry Data Security Standard

6 layers of protection

Comprehensive protection at every layer — from code to hardware.

🔒
Data encryption
Data at rest is encrypted with AES-256. Data in transit is protected by TLS 1.3. Keys are stored in HSM-compatible vaults and rotated every 90 days. BYOK (Bring Your Own Key) is supported for Enterprise customers.
👤
Access control
Role-Based Access Control (RBAC) with granular, object-level permissions. MFA is mandatory for every account. SSO via SAML 2.0 / OIDC. The principle of least privilege applies to all service accounts.
📋
Audit & logging
An immutable audit log for every action in the system: who, when, from which IP, what changed. Logs are retained for at least 365 days. Export to SIEM (Splunk, Datadog, ELK) via webhook or S3.
🏗
Infrastructure
Multi-tenant infrastructure with strict namespace-level isolation. Kubernetes with network policies and pod security standards. Every image is scanned by Trivy and Snyk before deployment. Runtime protection via Falco.
BCP / Disaster Recovery
RPO ≤ 1 hour, RTO ≤ 4 hours. Data replicated across 2+ availability zones. Daily backups with restore verification. DR drills run quarterly. SLA uptime 99.9% (Enterprise — 99.95%).
🛡
Secure development
OWASP Top-10 checks in CI. Static analysis (SonarQube, Semgrep) and DAST on staging. Mandatory security review for changes to auth, billing, and data-access layers. Weekly dependency audits.

Data residency

Choose a data storage region that matches your regulator's requirements.

RegionAvailable on plansNotes
🇪🇺EU (Frankfurt)DEFAULTFree, Pro, BusinessGDPR-compliant, default region
🇷🇺RU (Moscow)Business, Enterprise152-FZ, mirror + primary storage for RU customers
🇰🇿KZ (Almaty)EnterpriseLocal residency on regulator request
🏢Your VPCEnterpriseOn-premise / private cloud, BYOK, full isolation
BUG BOUNTY

Found a vulnerability? We pay for it.

Our Bug Bounty program is open to everyone. Rewards up to $5,000 for critical vulnerabilities (RCE, SQL injection, data leaks, authentication bypass). We respond within 48 hours. Responsible disclosure is mandatory.

Report a vulnerabilitysecurity@aevion.io

Request security documents

Documents are provided to current and prospective Business and Enterprise customers.

SOC 2 Report
The full Type II report is available on request under NDA for Enterprise and Business customers.
Request report
Data Processing Agreement (DPA)
A Data Processing Agreement for GDPR Article 28 compliance. Signed electronically within 1 business day.
Get DPA
Penetration Test Summary
A summary report of the annual penetration test performed by an independent firm. Available for Business and Enterprise.
Request pentest summary
Back to plans
Questions? security@aevion.io