Security Policy
Last updated: June 20, 2026
1. Our Commitment
At Avni Labs, we take the security of your campaign data and personal information seriously. We implement industry-standard security practices across our Platform and infrastructure.
2. Infrastructure Security
- All data is hosted on Amazon Web Services (AWS) infrastructure with enterprise-grade physical security
- Access to production systems is restricted to authorized personnel only
- All access is logged and monitored
- Infrastructure is regularly updated and patched
3. Data Encryption
- All data is encrypted in transit using TLS 1.2 or higher
- All data is encrypted at rest using AES-256
- Database backups are encrypted using the same standards
- API keys and credentials are stored using one-way hashing
4. Access Controls
- Role-based access control (RBAC) is enforced across all internal systems
- Multi-factor authentication (MFA) is required for all internal admin access
- Principle of least privilege is applied — no employee has more access than required
- Access is revoked immediately upon offboarding
5. Application Security
- Input validation and output encoding to prevent injection attacks
- CSRF protection on all state-changing endpoints
- Rate limiting and abuse detection on all public APIs
- Regular dependency audits and vulnerability scanning
- Secure coding practices reviewed in code reviews
6. Authentication
- Passwords are hashed using bcrypt with appropriate cost factors
- OAuth 2.0 is used for third-party login (Google)
- Session tokens are rotated on login and have short expiry windows
- Brute-force protection via rate limiting on authentication endpoints
7. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability, please:
1. Do not publicly disclose it before we have a chance to address it 2. Email us at security@avnilabs.ai with details 3. Include steps to reproduce, potential impact, and your contact information 4. Allow us a reasonable time to investigate and remediate
We commit to:
- Acknowledging your report within 48 hours
- Keeping you updated on our progress
- Not pursuing legal action for good-faith security research
8. Incident Response
In the event of a security incident:
- We will identify and contain the issue immediately
- Affected users will be notified without undue delay
- We will report to relevant authorities as required by law
- A post-incident review will be conducted to prevent recurrence
9. Third-Party Security
All third-party vendors and processors are evaluated for security compliance. Data processing agreements are in place with all vendors who handle personal data.
10. Employee Security
- All employees undergo security awareness training
- Background checks are conducted for roles with data access
- Security policies are reviewed and signed annually
- Employees use company-managed devices with endpoint protection
11. Compliance
Our security practices are aligned with:
- Digital Personal Data Protection Act, 2023 (DPDP Act), India
- ISO 27001 principles
- OWASP Top 10 mitigation guidelines
12. Contact
For security concerns or questions, contact:
Email: security@avnilabs.ai
Company: Avnira Technology Private Limited
Address: A/137-B G/F, Phase 5 Street No. 7, Aya Nagar, Delhi, India
