Avanoo docs
Security and privacy

Hosting, security, and compliance

Where Avanoo hosts data, who processes it, and which security and GDPR measures apply — for vendor reviews and DPOs.

This page covers residency, security measures, subprocessors, and compliance posture. For the data inventory itself, start with What Avanoo collects.

Hosting and residency

Avanoo is a multi-tenant SaaS. The application, databases, and backups run on Amazon Web Services in the European Economic Area:

  • Primary: AWS Europe (Paris), eu-west-3
  • Redundancy: AWS Europe (Frankfurt), eu-central-1

Customer data is stored and processed in these EU regions. Standard service delivery does not transfer usage data outside the EEA. Failover between Paris and Frankfurt is documented and manual.

Avanoo does not operate its own datacenter. There is no OVH or Google Cloud hosting path for the production service.

AI inference for the optional in-product assistant uses AWS Bedrock in the EU only.

The diagram below is the production architecture in the primary Paris region. Frankfurt is used for redundancy and is not shown.

Avanoo production architecture in AWS eu-west-3 (Paris). The web app at app.avanoo.ai authenticates administrators through Clerk into EC2. Browser extensions send application, email, and extension identifiers over HTTPS to API Gateway, a Lambda authorizer, SQS, and Lambda. Scheduled Lambdas call Microsoft Graph and other SaaS APIs. Data is written to S3 and to RDS inside a VPC, including a customer-dedicated RDS instance.

Encryption and keys

LayerMeasure
In transitTLS 1.2 or higher. Certificates issued and renewed through AWS Certificate Manager
At restAES-256 on RDS (PostgreSQL) and S3 (SSE-S3 or SSE-KMS)
KeysAWS KMS, no local key handling, access restricted and logged
BackupsEncrypted RDS snapshots (7-day default) and versioned S3 objects, with periodic restore tests

Isolation and access

  • Customer environments are logically isolated in the database and in logs. There is no application-level mixing of tenant data.
  • Dashboard access uses named accounts through SSO, with three roles: Read, Analyst, and Admin. Multi-factor authentication is enforced by the customer’s identity provider.
  • Avanoo staff access follows least privilege, named IAM accounts with MFA, and AWS SSO. Direct database access is forbidden except for maintenance.
  • Access to data, failed access, and suspicious behaviour are logged (AWS CloudTrail and GuardDuty). Logs are kept at least 12 months.

Subprocessors

Distinguish three things that vendor questionnaires often mix up.

Processors of customer data in the service

SubprocessorRoleLocation
Amazon Web ServicesHosts the application, databases, object storage, and backupsEEA (Paris, Frankfurt)
ClerkAuthenticates administrators of the Avanoo dashboard (SAML, OIDC, SCIM)See the DPA annex. Clerk does not identify employees in the browser extension
AWS BedrockOptional in-product assistantEU region only

The contractual list, retention, and notice period for changes are in the Data Processing Agreement annex. Avanoo notifies customers before adding or replacing a subprocessor.

Transfers outside the EEA, if any, use GDPR-appropriate safeguards such as the European Commission’s standard contractual clauses.

Not Avanoo subprocessors

  • Your identity providers (Microsoft Entra, Google Workspace, Okta, and others) remain your systems. Connecting them is optional and under your control.
  • GitHub is Avanoo’s source control. It does not host customer tenant data.
  • Google Workspace and Vanta are Avanoo internal collaboration and compliance tooling. They are not used to process your employees’ usage events.

GDPR

TopicPosition
RolesCustomer = controller. Avanoo = processor (DPA, GDPR Article 28)
DPOExternal DPO (law firm Acmai). Contact privacy@avanoo.ai or dpo@avanoo.ai
Security contactsecurity@avanoo.ai (CISO)
MinimisationMetadata only; allowlist; per-capability switches off by default; see What Avanoo collects
Employee information, DPIA, works councilCustomer responsibility. Avanoo provides the inventory and assistance
Breach notificationAvanoo notifies the customer as soon as possible by email and cooperates under Articles 33 and 34
End of contractOne month to request return or destruction; otherwise destruction within one year of the DPA ending

Avanoo is a French company: Avanoo SAS, 54 rue du Faubourg Poissonnière, 75010 Paris, SIREN 925 197 519.

Certifications

Avanoo does not currently hold ISO 27001, ISO 27701, SOC 2, SecNumCloud, or HDS certification of its own service.

What is in place:

  • A documented information-security policy (PSSI), available as a PDF on request.
  • Independent external penetration testing.
  • Internal security reviews.
  • An ISO/IEC 27001 programme (tooling via Vanta), with certification targeted for 2027. SOC 2 tracking is in the same programme; Avanoo is not SOC 2 certified today.
  • Hosting on AWS, which holds its own ISO 27001, SOC, and (in France) HDS attestations. Infrastructure questions about HDS or SecNumCloud therefore refer to the hosting provider, not to Avanoo’s application.

Continuity

Backups are automated and encrypted. Restore tests are periodic. A continuity and recovery plan covers failover between Paris and Frankfurt, with annual crisis exercises.

Documents available on request

Share these with a prospect, DPO, or works council rather than paraphrasing them:

  • Data Processing Agreement (processor contract, including the subprocessor annex)
  • This documentation: What Avanoo collects and this page
  • Privacy policy: avanoo.ai/legal/privacy-policy
  • Information-security policy (PSSI) and security-assurance plan
  • External penetration-test report, under NDA
  • Works-council briefing template, when the deployment is in France

For a feature-specific setting (which switches are on in a given tenant), the customer administrator exports the configuration from the platform, or asks their Avanoo representative.

On this page