Security and Compliance Built for Enterprise Trust

From encrypted data to rigorous security practices, Avoma is built to safeguard your business. We maintain SOC 2 Type II and ISO/IEC 42001:2023 certifications and support GDPR compliance.

How Avoma Protects Your Data

Avoma protects your data with robust security measures across our infrastructure, applications, and data systems. From AWS-hosted infrastructure and regular penetration testing to encryption at rest and in transit, security is built into every layer of the Avoma platform.

Data Center and Network Security

Avoma hosts all its software in Amazon Web Services (AWS) facilities in the USA. Amazon provides an extensive list of compliance and regulatory assurances. See Amazon's compliance and security documents for more detailed information.  100% of Avoma's primary application servers are located within Avoma's own virtual private cloud (VPC), protected by restricted security groups allowing only the minimal required communication to and between the servers.

Application Security

Avoma conducts application penetration testing by a third party at least annually in addition to Avoma's continued internal testing and review program.

Data Security

All connections to Avoma are encrypted using SSL, and any attempt to connect over HTTP is redirected to HTTPS. All customer data (including call recordings and transcripts) is encrypted at rest and in transit. We rely on AWS infrastructure to securely maintain our cryptographic encryption keys.  We use industry-standard AWS-managed PostgreSQL RDS and ElasticSearch data storage systems hosted within AWS.

Avoma Security, Compliance, and Certifications

Avoma combines industry-recognized certifications with robust privacy and compliance practices to help protect your data. Our security program includes SOC 2 Type II and ISO/IEC 42001:2023 certifications, along with controls that support GDPR and recording consent requirements.

GDPR Compliance

Avoma is committed to ensuring General Data Protection Regulation (GDPR) compliance with built-in, customizable controls to obtain unambiguous consent for all your calls and meetings.

Avoma facilitates GDPR compliance with:
  • Notifications to help you gain consent to record meetings and calls
  • The control to access and request to delete data
  • A clear privacy policy on why and how we collect data, and what we do with it.

SOC 2 Type II Certified

Avoma provides enterprise-level security for customer data secured in our systems. Our current and future customers can be assured we manage their data with the highest standard of security and compliance. Our design, security and operations have been successfully evaluated and certified by an independent audit for SOC 2 Type II compliance. As we continue to work with mid-market and enterprise clients, we’re committed to share our compliance report as required.

ISO/IEC 42001:2023 Certified

Avoma is certified to ISO/IEC 42001:2023, the international standard for Artificial Intelligence Management Systems (AIMS). This certification reflects our commitment to developing and operating AI responsibly through structured governance, risk management, transparency, and continuous improvement. Our AI management practices have been independently evaluated against the standard’s requirements, giving customers confidence that Avoma manages AI risks and opportunities with accountability while continuing to innovate responsibly.‍
ISO42001 Certified  Avoma
Avoma Recording Consent Compliance

Recording Consent Compliance

Across the United States, European Union, and other regions, there are mandates on notifying and seeking consent before the meetings and calls are recorded. Some countries or states might require you to seek active consent from both parties, whereas in some other places one-party consent might suffice. As a compliance best practice, we recommend turning on the “Meeting Reminder to Participants + Recording Consent Disclaimer” notification especially for the external participants, regardless of their location.

Security and Development Practices

  • Design of all new product functionality is reviewed for security impact, with Avoma conducting mandatory code reviews for all changes to the code. Avoma’s development and testing environments are separate from its production environment. All code development is done through a standard process. 
  • Vulnerability Disclosure Process – Avoma considers privacy and security to be the core functions of our platform. Earning and keeping the trust of our customers is our top priority; therefore, we hold ourselves to the highest privacy and security standards. If you have discovered a security or privacy issue that you believe we should know about, we would be eager to hear from you. 

Looking for Avoma's latest security documentation?
Access certifications, audit reports, security documentation, and compliance resources in the Avoma Trust Center.

Please reach out to us at security@avoma.com with questions. We have a policy of responding to security reports within 24 hours.