Security & Privacy

Safe, secure and private

Security is not a feature for us — it is the foundation. Every decision we make protects your data, your students, and your institution.

SOC 2 Type II
Certified infrastructure
TLS 1.3
Data in transit
AES-256
Data at rest
HIPAA-Aligned
Healthcare privacy design
Our Commitments

Security pillars

End-to-End Encryption

All data in transit is encrypted with TLS 1.3. Data at rest uses AES-256. Your sessions, transcripts, and client profiles are never stored in plaintext.

Zero Data Retention

Session audio and transcripts are processed in-memory and never persisted beyond your explicit storage preferences. You own your data, full stop.

Secure Infrastructure

Hosted on SOC 2 Type II certified infrastructure with redundant, isolated compute environments. Regular third-party penetration tests keep us sharp.

No Training on Your Data

We never use your sessions or client interactions to train our models. Your practice data stays private — it is not a product for us.

Role-Based Access

Granular permission levels for students, supervisors, and administrators. Only the right people see the right data, always.

HIPAA-Aligned Design

Our architecture follows HIPAA technical safeguard guidelines — access logs, audit trails, and automatic session timeouts are built in.

Proactive Security

We act before problems arise

Rather than reacting to incidents, we invest heavily in preventative security practices, continuous monitoring, and a culture where every engineer considers security a first-class concern.

Penetration Testing

We engage independent security firms to conduct quarterly penetration tests across our API and infrastructure.

Bug Bounty Program

Responsible disclosure is rewarded. Submit vulnerabilities through our security portal and we will respond within 48 hours.

Audit Logs

Every access event, configuration change, and API call is logged with immutable timestamps for complete accountability.

Automatic Updates

Security patches are applied automatically with zero downtime, keeping your environment protected without any action required.

Found a vulnerability?

We have a responsible disclosure program and will respond to all valid reports within 48 hours. Your help makes Auven safer for everyone.

Report a vulnerability

Train with confidence