# Security information

## 🇫🇷  Hosting <a href="#hosting" id="hosting"></a>

All of our data and application is hosted in France on AWS Servers (eu-west-3).

## 🔐 Compliance <a href="#compliance" id="compliance"></a>

<figure><img src="/files/SJSin4P2qGHMrknF6lft" alt=""><figcaption></figcaption></figure>

## ☁️ Sub-Providers <a href="#sub-providers" id="sub-providers"></a>

Our main sub-providers are : AWS (cloud), Google (IdP), Microsoft (IdP), Okta (IdP), Github (Version Control)

## ⚙️ Infrastructure schema

<figure><img src="/files/BJOJwchh3QJqdulBpLt3" alt=""><figcaption></figcaption></figure>

## ⚙️ Functional levels

Our solution offers three distinct levels of functionality plus an extra

### Premium - Diagnostic:&#x20;

A one-time in-depth automatic diagnostic to uncover Shadow IT, prevent security risks, cut down on unused tool costs and pinpoint critical concerns.

#### Anonymous Collection:&#x20;

This level provides anonymous data collection, tracking usage events such as timestamps and accessed domains across 110,000+ whitelisted domains. It is ideal for environments needing high security with minimal data exposure.

#### Identified Collection:

In addition to basic monitoring, this level includes identified data collection. It captures user-specific information like email addresses and domain cookies to ensure accurate tracking of user activity. This level also supports integration with major IdPs (Microsoft, Okta, Google) for directory and SSO event synchronization. Examples of outcomes include identifying unauthorized SaaS usage or detecting policy violations based on user activity.

### Business Plan - Shadow IT&#x20;

Manage Shadow IT effortlessly with the Business Package, offering real-time monitoring and proactive protection for all online tools used by your teams.&#x20;

### Enterprise plan - Shadow IT & FinOps:&#x20;

Streamline SaaS management with the Enterprise package, offering smarter cost control and spend management systems alongside with advanced security features.

### Advanced Software Analysis

This specific use case focuses on timely audits and reviews, providing a comprehensive overview of a SaaS real usage—ideal for contract renewals, for example. Deliverables are provided as Excel sheets, offering significantly more data than what is available in Avanoo’s web app.

## 🙅 Data collected : <a href="#the-data-collected" id="the-data-collected"></a>

### IdP (Google Workspace, Okta, Microsoft Entra, CSV)

<table><thead><tr><th>SSO Integrations</th><th width="121" data-type="checkbox">Anonymous</th><th width="108" data-type="checkbox">Identified</th><th data-type="checkbox">Advanced software analysis</th></tr></thead><tbody><tr><td>List of Users (email, name, Id, team, admin status)</td><td>false</td><td>true</td><td>true</td></tr><tr><td>Users relationship (manager)</td><td>false</td><td>true</td><td>true</td></tr><tr><td>Groups and Organization units</td><td>false</td><td>true</td><td>true</td></tr><tr><td>Historical log events</td><td>false</td><td>true</td><td>false</td></tr><tr><td>Token of authentifications for external apps</td><td>false</td><td>true</td><td>false</td></tr><tr><td>Timestamp of tokens</td><td>false</td><td>true</td><td>false</td></tr><tr><td>Scopes granted to external apps</td><td>false</td><td>true</td><td>false</td></tr></tbody></table>

### Browser extensions (Chrome, Chromium, Edge, Firefox, Safari)

<table><thead><tr><th>Browser extensions</th><th width="125" data-type="checkbox">Anonymous</th><th width="110" data-type="checkbox">Identified</th><th data-type="checkbox">Advanced software analysis</th></tr></thead><tbody><tr><td>URLs</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Email used to connect</td><td>false</td><td>true</td><td>false</td></tr><tr><td>Timestamp</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Users nudge responses</td><td>false</td><td>true</td><td>false</td></tr></tbody></table>

### 2000+ integrations

<table><thead><tr><th>Direct Integrations to SaaS Apps</th><th width="128" data-type="checkbox">Anonymous</th><th width="110" data-type="checkbox">Identified</th><th data-type="checkbox">Advanced software analysis</th></tr></thead><tbody><tr><td>Users</td><td>false</td><td>true</td><td>true</td></tr><tr><td>Authentification method</td><td>false</td><td>true</td><td>false</td></tr><tr><td>Date of creation and desactivation</td><td>false</td><td>true</td><td>true</td></tr><tr><td>Permissions and licences levels</td><td>false</td><td>true</td><td>true</td></tr><tr><td>Historical events</td><td>false</td><td>true</td><td>true</td></tr></tbody></table>

### Google Workspace and Microsoft Office 365

<table><thead><tr><th>Emails</th><th width="128" data-type="checkbox">Anonymous</th><th width="106" data-type="checkbox">Identified</th><th data-type="checkbox">Advanced software analysis</th></tr></thead><tbody><tr><td>UserId</td><td>false</td><td>true</td><td>false</td></tr><tr><td>VendorId</td><td>false</td><td>true</td><td>false</td></tr><tr><td>Timestamp</td><td>false</td><td>true</td><td>false</td></tr></tbody></table>

## 🗄️ Recognised Applications: <a href="#recognised-applications" id="recognised-applications"></a>

All applications that are part of our database can be recognised by both the SSO, the browser agent and the emails addons. This whitelist currently contains more than 110,000 apps. This whitelist is also :

* Customizable.
* Weekly updated, especially with new AI tool.
* Can contain custom client URLS for on premise applications accessed via the browser.

## 📗GDPR Compliance and Validation:&#x20;

All solutions are GDPR compliant, addressing the stringent data protection requirements of the insurance industry.&#x20;

The anonymous option is particularly beneficial in security-sensitive environments, as it only collects usage events without personal information. Furthermore, all data traffic is encrypted to prevent leakage in case of interception. Upon receipt, traffic is secured using AWS Cognito resource access control, ensuring no unauthorized access.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.avanoo.ai/public-knowledge-base/security-information.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
