Safe, secure and private
Security is not a feature for us — it is the foundation. Every decision we make protects your data, your students, and your institution.
Security pillars
End-to-End Encryption
All data in transit is encrypted with TLS 1.3. Data at rest uses AES-256. Your sessions, transcripts, and client profiles are never stored in plaintext.
Zero Data Retention
Session audio and transcripts are processed in-memory and never persisted beyond your explicit storage preferences. You own your data, full stop.
Secure Infrastructure
Hosted on SOC 2 Type II certified infrastructure with redundant, isolated compute environments. Regular third-party penetration tests keep us sharp.
No Training on Your Data
We never use your sessions or client interactions to train our models. Your practice data stays private — it is not a product for us.
Role-Based Access
Granular permission levels for students, supervisors, and administrators. Only the right people see the right data, always.
HIPAA-Aligned Design
Our architecture follows HIPAA technical safeguard guidelines — access logs, audit trails, and automatic session timeouts are built in.
We act before problems arise
Rather than reacting to incidents, we invest heavily in preventative security practices, continuous monitoring, and a culture where every engineer considers security a first-class concern.
Penetration Testing
We engage independent security firms to conduct quarterly penetration tests across our API and infrastructure.
Bug Bounty Program
Responsible disclosure is rewarded. Submit vulnerabilities through our security portal and we will respond within 48 hours.
Audit Logs
Every access event, configuration change, and API call is logged with immutable timestamps for complete accountability.
Automatic Updates
Security patches are applied automatically with zero downtime, keeping your environment protected without any action required.
Found a vulnerability?
We have a responsible disclosure program and will respond to all valid reports within 48 hours. Your help makes Auven safer for everyone.
Report a vulnerability