Skip to content
AVENI ABOUT US TRUST & SECURITY

Built for financial services. Designed for trust.

At Aveni, trust isn't a feature – it's the foundation of everything we build. Our platform is engineered to meet the standards of regulated financial institutions where data sensitivity, compliance, and operational resilience are non-negotiable. Giving you confidence that your data, your customers, and your business are protected.

ISO 27001 Certified
GDPR Compliant
AES-256 AWS
Privacy by Design
The four pillars

Trust at every layer of the platform.

Security, compliance, responsible AI and resilience – engineered together. Drag, scroll or use the arrows to step through each pillar.

Pillar 01 · Security

Security you can rely on.

Data encryption

Protected in transit using modern TLS protocols and encrypted at rest using AES-256. Keys are managed securely and rotated regularly to reduce long-term exposure.

Secure cloud infrastructure

Aveni runs on AWS. All data is encrypted at rest, each customer's data is isolated, and continuous monitoring and threat detection are in place to keep data secure.

Access controls & 2FA

2FA enforced across all accounts. Strict role-based permissions, all admin access logged, periodically reviewed, and requiring explicit security approval before granting.

Employee security & vetting

Every Aveni employee undergoes background checks and signs a confidentiality agreement. Devices are secured via MDM, with hard-drive encryption and anti-malware on every machine.

TLS AES-256 RBAC 2FA MDM
Pillar 02 · Compliance

Built for regulated environments.

Aveni is purpose-built for financial services – compliance and governance are embedded into how we operate, not bolted on.

ISO 27001 certified

The globally recognised standard for protecting information assets – independently validating our controls for confidentiality, integrity, and availability across the full organisation.

GDPR & UK GDPR compliant

Full adherence to UK and EU GDPR. Lawful basis, data subject rights, and purpose limitation are embedded into how we operate – protecting your customers' rights at every step.

Audit-ready by design

Clear traceability and documentation at every stage. For internal governance or external regulatory review – Consumer Duty KPI monitoring, FCA reporting, record keeping covered.

Purpose-built for regulated firms

100% call and document monitoring coverage – supporting Consumer Duty, suitability, conduct, and customer vulnerability obligations across your business.

ISO 27001 UK GDPR FCA Consumer Duty
Pillar 03 · Responsible AI

Responsible AI you can trust.

AI in financial services must be transparent, controlled, and aligned with regulation. That's exactly how we build.

No black boxes

Explainability is prioritised in how our models operate. Activity traces, source citation, and decision logs give you clarity into how Aveni reached its conclusions – essential for regulated decision-making.

Human oversight always

Our tools are designed to support professionals, not replace them. Humans remain firmly in control of every decision. Aveni surfaces intelligence and flags risk – final judgement always rests with your team.

Domain-specific models

Our AI – including FinLLM – is trained specifically for financial services. Domain-specific training reduces hallucination risk, improves accuracy, and aligns with regulatory language.

Your data is never used for training

Customer and call data is never used to train our AI systems or those of any third-party AI provider. Applied as a technical constraint and enforced contractually – not left to policy alone.

TLS AES-256 RBAC 2FA MDM
Pillar 04 · Resilience

Operational resilience.

Our platform supports critical business processes. That's why reliability is built in at every level.

High availability architecture

Engineered for uptime and continuity. Aveni's infrastructure supports the critical business processes of regulated firms, with redundancy built in at every level to minimise disruption.

Backup & disaster recovery

Robust backup processes and tested disaster recovery plans. Users retain full control over their data lifecycle, with automated deletion schedules and manual clearing at any time.

Incident response

Clear, tested processes are in place to detect, respond to, and resolve security events quickly and transparently – with proactive communication to affected parties.

Continuous monitoring

We proactively monitor for threats, vulnerabilities, and unusual activity across all systems. All internal access is logged and reviewed on a regular cadence.

HA DR Incident response 24/7 monitoring
Verified credentials

Standards you can verify.

Our certifications are independently assessed and maintained – giving compliance, legal, and procurement teams the documented evidence they need.

Certified

ISO 27001

International standard for information security management systems. Independently certified – covering confidentiality, integrity, and availability of information assets across the entire organisation.
Compliant

GDPR / UK GDPR

Full compliance with both EU and UK General Data Protection Regulation. Lawful basis for processing, data subject rights, and privacy-by-design principles embedded across operations and product.
Active

AWS AES-256 Encryption

Data stored on AWS S3 with Server Side Encryption enabled. 256-bit AES applied to all buckets and volumes. Encryption keys managed with a regularly rotated root key for sustained cryptographic integrity.
Active

Privacy by Design

Privacy embedded at architecture level from day one. Consent-first recording, data minimisation, user-controlled retention, and invite-only meeting capture are core product behaviours.
Data ownership

Your data stays yours. Full stop.

We don't use your data to train general-purpose models, share it with third parties, or retain it beyond the purposes of delivering our services to you – always in line with agreed terms and applicable regulations.

Customer call data is never used to train Aveni's AI models

Third-party AI providers are never trained on your data

Aveni only records meetings it is explicitly invited to join

You control what is recorded, what is shared, and when it is deleted

Conversations are private and accessible only to authorised users

Data is processed solely to deliver our services – nothing else

We understand that your discussions often involve highly sensitive and confidential data. That's why privacy and security are not policy documents at Aveni – they're design requirements embedded into every product decision we make.

Aveni Engineering
Under the hood

Your data. Protected.

For technical reviewers, infosec teams, and procurement – the specifics of how we protect your data and environment.

spec_01 · encryption

AES-256 at Rest & in Transit | aws-s3-sse

AWS S3 Server Side Encryption enabled across all data buckets and machine volumes. 256-bit AES applied end-to-end. Root encryption key rotated regularly – removing long-term static exposure.

Active
spec_02 · authentication

2FA & Role-Based Access | rbac

Two-factor authentication enforced across all accounts. Internal admin access requires explicit security approval and is restricted to job-function necessity. All events logged and reviewed.

Enforced
spec_03 · devices

MDM & Endpoint Controls | jamf

All employee devices enrolled in mobile device management. Hard-drive encryption enforced by default. Anti-malware installed, maintained and centrally managed across the entire device fleet.

Managed
spec_04 · people

Vetted, Bound Employees | bg-check

Clean cases flow through. Higher- risk cases route to reviewers with evidence pre-gathered. Scale assurance without scaling headcount.

Vetted
spec_05 · infrastructure

Isolated Production Environments | aws-vpc

Customer data provisioned in isolated AWS production projects. Complete logical separation between organisations. No data from one customer is accessible to another.

Isolated
spec_06 · lifecycle

Controlled Retention & Deletion | 30d-trash

Users control their own data lifecycle. Conversations automatically purged after 30 days in trash. Manual deletion is honoured immediately. No data persists beyond agreed retention terms.

User-controlled
Common questions

Security & trust – answered.

The questions we hear most from compliance leads, infosec teams, and procurement during due diligence.

Are customer calls or transcriptions used to train Aveni's AI models?

No. Customer and call data is never used to train Aveni's models, and never passed to a third-party AI provider for training either. That is applied as a technical control, not just a contractual promise — your data is processed solely to deliver the service to you.

How is data encrypted and where is it stored?

In transit over modern TLS, and at rest with 256-bit AES. Data is held on AWS with Server Side Encryption enabled across every bucket and machine volume, and the root encryption key is rotated regularly so there is no long-term static exposure.

Who can access call recordings and transcripts?

Only the authorised users in your own organisation. Each customer is provisioned in an isolated AWS production project with complete logical separation, so no data from one organisation is reachable from another. Internal admin access requires explicit security approval, is restricted to job-function necessity, is protected by enforced 2FA, and every event is logged and reviewed.

How does Aveni help meet FCA and Consumer Duty requirements?

By giving you 100% coverage of calls and documents rather than a sample, with clear traceability and documentation at every stage. That supports Consumer Duty, suitability, conduct and customer vulnerability obligations, and it is audit-ready by design — for internal governance or external regulatory review.

What happens to our data when we delete it?

You control your own data lifecycle. Manual deletion is honoured immediately, conversations in trash are purged automatically after 30 days, and no data persists beyond the retention terms you have agreed.

How does Aveni control which meetings the AI joins?

Aveni only records meetings it has been explicitly invited to join — capture is invite-only and consent-first by design. You control what is recorded, what is shared, and when it is deleted.

Can we review security documentation for due diligence?

Yes. We are ISO 27001 certified and GDPR / UK GDPR compliant, and we share the supporting documentation with compliance, infosec and procurement teams as part of due diligence. Contact us and we will route the request to the right team.

Work with confidence.

Trusted by financial institutions who cannot afford to compromise. Evaluating Aveni? We're ready to support your security review – with documentation, direct answers, and a team that understands your regulatory environment.