Skip to main content

Governance, Policy, and Compliance

Policy Framework

Avoca maintains documented security and privacy policies that support its control environment and SOC 2 program. Policies have assigned owners and are reviewed on a recurring basis or when material changes require an earlier review. The framework covers topics such as:
  • Access control and acceptable use
  • Secure development and change management
  • Risk, vulnerability, and vendor management
  • Incident response and business continuity
  • Data handling, retention, and privacy
  • Personnel security and security awareness

Incident Response and Business Continuity

Avoca maintains incident-response and business-continuity procedures for identifying, containing, investigating, recovering from, and learning from security or availability events. Response activities are coordinated across the relevant engineering, leadership, legal, customer, and provider contacts. Exercises, reviews, and operational events are used to improve the procedures over time.

Regulatory and Contractual Commitments

Security and privacy obligations vary by customer, data set, product configuration, and applicable law. Avoca evaluates those obligations through its contracts, data-processing terms, policies, and control program.
A security certification does not by itself make every customer workflow compliant with every regulation. Customers remain responsible for configuring and using Avoca consistently with their own legal and regulatory obligations.

Incident Communication

When an incident requires customer notification, Avoca follows the timing, content, and delivery requirements in applicable law and customer agreements. Communications are designed to provide the confirmed scope, customer impact, protective actions, and material updates available at that stage of the response. For a copy of applicable security or data-processing terms, contact your Avoca account team.