AVAV runs systems that hold payroll records, student information and customer conversations, so trust isn't optional. This page sets out, plainly, how we protect your data: POPIA-aligned processing, encryption in transit and at rest, role-based access, audit trails, backups and a clear way to report a problem. We describe what we do, and we don't claim certifications we don't hold.
These are the controls we apply across our products. Where a detail depends on your deployment, we'll confirm it during implementation.
Information is protected both while it moves and while it is stored. Traffic between your browser and our servers is encrypted with TLS, and data stored in our hosting environment is encrypted at rest.
People should only see what their job requires. Our products use role-based access control so permissions match responsibilities, and administrative access is limited to the team members who need it to run and support the service.
Key actions are recorded so that access and changes can be reviewed. Audit trails support accountability day to day and make it possible to investigate if something looks out of place.
We take regular backups so data can be restored, and host on infrastructure designed for reliable availability. We monitor the service and work to restore it quickly if an incident occurs.
POPIA isn't a bolt-on for us. Because we build for South African organisations, protecting personal information is part of how the products are designed.
We process personal information for a clear, lawful purpose, and limit what we collect and how long we keep it to what the purpose requires.
Where AVAV acts as an operator processing personal information on a client's behalf, we put POPIA-compliant processing agreements in place setting out responsibilities and safeguards.
We apply appropriate technical and organisational safeguards, encryption, access control, audit trails, to protect personal information against loss or unauthorised access.
Our products are built to support the rights POPIA gives people over their information, and we help clients meet requests relating to the data they hold in our systems.
This page describes our approach in good faith and is not legal advice. Your organisation remains responsible for its own POPIA obligations as a responsible party. For how AVAV handles personal information, see our Privacy Policy and Terms.
If you believe you've found a security vulnerability in an AVAV product or service, please let us know so we can fix it. Email info@avav.co.za with enough detail for us to reproduce and understand the issue.
We take legitimate reports seriously: we'll acknowledge your report, investigate, and keep you informed as we work on a fix. We ask that you give us reasonable time to address an issue before disclosing it publicly, and that you avoid accessing or altering data that isn't yours while testing.
We're grateful to the researchers and users who help us keep our systems safe.
AVAV builds and operates its products in line with POPIA. We process personal information for a lawful purpose, limit what we collect and keep, apply appropriate security safeguards, and put processing agreements in place where AVAV acts as an operator for a client.
Data is encrypted in transit using TLS, and encrypted at rest in our hosting environment. This protects information both while it moves between your browser and our servers and while it is stored.
Access is governed by role-based access control, so people only see what their role requires. Administrative access is limited to the team members who need it to operate and support the service, and access to client data is kept to what is necessary.
Yes. Our products maintain audit trails of key actions so that changes and access can be reviewed. This supports accountability and helps with investigations if something looks wrong.
We take regular backups so data can be restored, and we host on infrastructure designed for reliable availability. We monitor the service and work to restore it quickly if an incident occurs.
We describe our practices honestly and don't claim certifications we don't hold. Our approach follows recognised good practice, encryption, access control, audit trails, backups and POPIA-aligned processing. If your procurement needs specific documentation, contact us and we'll share what we can.
Please email info@avav.co.za with details of the issue. We take responsible disclosure seriously and will acknowledge and investigate legitimate reports. Please give us reasonable time to address an issue before disclosing it publicly.
Book a free discovery call. We'll walk your team through how AVAV protects your data, honestly.
Response within 24 hours