logo

Security Policy

Last updated: June 20, 2026

1. Our Commitment

At Avni Labs, we take the security of your campaign data and personal information seriously. We implement industry-standard security practices across our Platform and infrastructure.

2. Infrastructure Security

  • All data is hosted on Amazon Web Services (AWS) infrastructure with enterprise-grade physical security
  • Access to production systems is restricted to authorized personnel only
  • All access is logged and monitored
  • Infrastructure is regularly updated and patched

3. Data Encryption

  • All data is encrypted in transit using TLS 1.2 or higher
  • All data is encrypted at rest using AES-256
  • Database backups are encrypted using the same standards
  • API keys and credentials are stored using one-way hashing

4. Access Controls

  • Role-based access control (RBAC) is enforced across all internal systems
  • Multi-factor authentication (MFA) is required for all internal admin access
  • Principle of least privilege is applied — no employee has more access than required
  • Access is revoked immediately upon offboarding

5. Application Security

  • Input validation and output encoding to prevent injection attacks
  • CSRF protection on all state-changing endpoints
  • Rate limiting and abuse detection on all public APIs
  • Regular dependency audits and vulnerability scanning
  • Secure coding practices reviewed in code reviews

6. Authentication

  • Passwords are hashed using bcrypt with appropriate cost factors
  • OAuth 2.0 is used for third-party login (Google)
  • Session tokens are rotated on login and have short expiry windows
  • Brute-force protection via rate limiting on authentication endpoints

7. Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability, please:

1. Do not publicly disclose it before we have a chance to address it 2. Email us at security@avnilabs.ai with details 3. Include steps to reproduce, potential impact, and your contact information 4. Allow us a reasonable time to investigate and remediate

We commit to:

  • Acknowledging your report within 48 hours
  • Keeping you updated on our progress
  • Not pursuing legal action for good-faith security research

8. Incident Response

In the event of a security incident:

  • We will identify and contain the issue immediately
  • Affected users will be notified without undue delay
  • We will report to relevant authorities as required by law
  • A post-incident review will be conducted to prevent recurrence

9. Third-Party Security

All third-party vendors and processors are evaluated for security compliance. Data processing agreements are in place with all vendors who handle personal data.

10. Employee Security

  • All employees undergo security awareness training
  • Background checks are conducted for roles with data access
  • Security policies are reviewed and signed annually
  • Employees use company-managed devices with endpoint protection

11. Compliance

Our security practices are aligned with:

  • Digital Personal Data Protection Act, 2023 (DPDP Act), India
  • ISO 27001 principles
  • OWASP Top 10 mitigation guidelines

12. Contact

For security concerns or questions, contact:

Email: security@avnilabs.ai
Company: Avnira Technology Private Limited
Address: A/137-B G/F, Phase 5 Street No. 7, Aya Nagar, Delhi, India