Security assurance

Aiva security assurance is published from one shared programme.

This page is the public starting point for Aiva security assurance. It points to the controls, operating guidance, and reporting paths that customers ask for before they buy. Only approved, current answers should be published, and anything product-specific must be checked against the live deployment before it is stated publicly.

Current posture

Aiva uses the shared VERLOX security assurance process for reviews, questionnaire answers, and public claims. The public page never becomes the source of truth on its own.

What to ask for

  • Encryption and secrets handling
  • Access control and audit trails
  • Backups and recovery approach
  • Incident response and vulnerability reporting

What is not published here

Unreviewed certifications, dates, regions, retention periods, pen test results, or any claim that is not backed by the current assurance record.

Escalation option

Optional human escalation remains available for judgment-heavy cases. It is not required for day-to-day Aiva operation and is arranged with VERLOX when needed.

How we answer security questionnaires

Answers are maintained in the shared assurance programme, checked against the current deployment, and only published when they match product reality. If the question combines multiple controls, each part should be answered separately and qualified where needed.

  • Use current, product-specific facts only
  • Do not turn planned work into current capability
  • Do not publish stronger wording than the evidence supports