--- title: "Aivastark — Security & Privacy" description: "Aivastark security posture, data-residency and privacy commitments, compliance position, and vulnerability disclosure policy." canonical: "https://www.aivastark.com/security" source: "https://www.aivastark.com/security.md" updated: "2026-08-12" --- # Aivastark — Security & Privacy > Aivastark security posture, data-residency and privacy commitments, compliance position, and vulnerability disclosure policy. Your data stays in your own Supabase project, in your region. Aivastark never trains shared foundation models on your content, and personally identifiable information is redacted before it reaches the model. ## Security posture - **Certification** — SOC 2 Type II. - **Encryption in transit** — TLS 1.2+ on all traffic. - **Encryption at rest** — AES-256. - **Passwords** — Hashed with a modern, slow algorithm. - **Production access** — Restricted to a small set of engineers, multi-factor required. - **Tenancy** — Embeddings and conversation data are scoped per organization and never co-mingled. - **Audit logs** — Administrative actions are logged and retained. ## Privacy & compliance - **Model training** — Aivastark never trains shared foundation models on your content. - **PII** — Redacted before it reaches the model. - **Data residency** — Your knowledge-base embeddings live in your own Supabase project, in your region. EU data residency is available on Enterprise. - **GDPR** — An Article 28 Data Processing Agreement is included on every plan. - **HIPAA** — HIPAA-readiness documentation is available under NDA; a Business Associate Agreement is available on Enterprise. - **SSO** — SAML/OIDC single sign-on is available on Enterprise. - **Retention** — Conversation auto-purge can be scheduled. Full CSV export at any time. - **Exit** — Cancel and your data leaves with you. ## Visitor analytics Visitor Lenz is cookieless — page views, referrers, geography and device are ingested server-side, so no cookie banner is required for it. It can be disabled per widget. ## Vulnerability disclosure Report vulnerabilities to security@aivastark.com with reproduction steps, and please allow a reasonable remediation window before public disclosure. The canonical policy is published at /.well-known/security.txt. Security contact: [security@aivastark.com](mailto:security@aivastark.com) · https://www.aivastark.com/.well-known/security.txt ## Legal documents - [Security overview](https://www.aivastark.com/security) - [Privacy policy](https://www.aivastark.com/privacy) - [Terms of service](https://www.aivastark.com/terms) - [Data Processing Agreement](https://www.aivastark.com/dpa) - [Sub-processors](https://www.aivastark.com/sub-processors) --- *Aivastark · https://www.aivastark.com · updated 2026-08-12* This document is machine-readable documentation for AI assistants and search engines. The complete index is at https://www.aivastark.com/llms.txt and the full corpus at https://www.aivastark.com/llms-full.txt. The human-readable version of this page is https://www.aivastark.com/security. Questions: support@aivastark.com · Security: security@aivastark.com