Back to homeLegal

Security & Compliance

Last updated: 31 May 2025

We treat security as a first-class engineering discipline. Every system we build is designed with security from the first architecture decision — not added at the end.

Security Practices

Data Encryption

TLS encryption for data in transit. Sensitive data encrypted at rest using industry-standard algorithms, configured per platform and scope.

Access Controls

Role-based access control (RBAC) and least-privilege permissions. Multi-factor authentication required for all internal systems.

Security Monitoring

Monitoring, threat detection, centralised logging, and alerting configured for production environments based on risk and operational needs.

Infrastructure Security

Cloud architecture includes network isolation, security groups, WAF controls, secret management, and coordinated penetration testing.

Secure Development Lifecycle

01

Threat Modelling

Security requirements and threat analysis during architecture design — before any code is written.

02

Secure Coding

OWASP-aligned coding standards, input validation, parameterised queries, and secure dependency management.

03

Static Analysis

Automated SAST scanning on every pull request. Dependency vulnerability scanning with automated tooling.

04

Code Review

Security-focused peer review on all code changes. No direct commits to main or production branches.

05

Penetration Testing

Periodic third-party penetration testing for client-facing applications and APIs.

06

Incident Response

Documented incident response plan with defined SLAs for detection, containment, and notification.

Compliance Standards

GDPRPrivacy-aware design for solutions handling EU/EEA user data
PCI DSSPayment processing via Stripe (PCI DSS Level 1 certified)
HIPAA-AwareHealthcare security requirements for applicable engagements
SOC 2-AlignedControls mappable to SOC 2 readiness requirements
ISO 27001Information security management framework alignment
OWASP Top 10Applications tested against OWASP Top 10 vulnerabilities

Responsible Disclosure

If you discover a potential security vulnerability in any Avantika Technology product or service, please report it confidentially before making it public. We commit to:

  • Respond within 48 hours of receipt
  • Work with you on coordinated, responsible disclosure
  • Acknowledge your contribution if desired
  • Not pursue legal action for good-faith security research
Report a Vulnerability

Have a question about this policy?

Contact us directly and we will respond within one business day.

Email Us
1