Built for financial services. Designed for trust.
At Aveni, trust isn't a feature – it's the foundation of everything we build. Our platform is engineered to meet the standards of regulated financial institutions where data sensitivity, compliance, and operational resilience are non-negotiable. Giving you confidence that your data, your customers, and your business are protected.
Trust at every layer of the platform.
Security, compliance, responsible AI and resilience – engineered together. Drag, scroll or use the arrows to step through each pillar.
Security you can rely on.
Data encryption
Protected in transit using modern TLS protocols and encrypted at rest using AES-256. Keys are managed securely and rotated regularly to reduce long-term exposure.
Secure cloud infrastructure
Aveni runs on AWS. All data is encrypted at rest, each customer's data is isolated, and continuous monitoring and threat detection are in place to keep data secure.
Access controls & 2FA
2FA enforced across all accounts. Strict role-based permissions, all admin access logged, periodically reviewed, and requiring explicit security approval before granting.
Employee security & vetting
Every Aveni employee undergoes background checks and signs a confidentiality agreement. Devices are secured via MDM, with hard-drive encryption and anti-malware on every machine.
Built for regulated environments.
Aveni is purpose-built for financial services – compliance and governance are embedded into how we operate, not bolted on.
ISO 27001 certified
The globally recognised standard for protecting information assets – independently validating our controls for confidentiality, integrity, and availability across the full organisation.
GDPR & UK GDPR compliant
Full adherence to UK and EU GDPR. Lawful basis, data subject rights, and purpose limitation are embedded into how we operate – protecting your customers' rights at every step.
Audit-ready by design
Clear traceability and documentation at every stage. For internal governance or external regulatory review – Consumer Duty KPI monitoring, FCA reporting, record keeping covered.
Purpose-built for regulated firms
100% call and document monitoring coverage – supporting Consumer Duty, suitability, conduct, and customer vulnerability obligations across your business.
Responsible AI you can trust.
AI in financial services must be transparent, controlled, and aligned with regulation. That's exactly how we build.
No black boxes
Explainability is prioritised in how our models operate. Activity traces, source citation, and decision logs give you clarity into how Aveni reached its conclusions – essential for regulated decision-making.
Human oversight always
Our tools are designed to support professionals, not replace them. Humans remain firmly in control of every decision. Aveni surfaces intelligence and flags risk – final judgement always rests with your team.
Domain-specific models
Our AI – including FinLLM – is trained specifically for financial services. Domain-specific training reduces hallucination risk, improves accuracy, and aligns with regulatory language.
Your data is never used for training
Customer and call data is never used to train our AI systems or those of any third-party AI provider. Applied as a technical constraint and enforced contractually – not left to policy alone.
Operational resilience.
Our platform supports critical business processes. That's why reliability is built in at every level.
High availability architecture
Engineered for uptime and continuity. Aveni's infrastructure supports the critical business processes of regulated firms, with redundancy built in at every level to minimise disruption.
Backup & disaster recovery
Robust backup processes and tested disaster recovery plans. Users retain full control over their data lifecycle, with automated deletion schedules and manual clearing at any time.
Incident response
Clear, tested processes are in place to detect, respond to, and resolve security events quickly and transparently – with proactive communication to affected parties.
Continuous monitoring
We proactively monitor for threats, vulnerabilities, and unusual activity across all systems. All internal access is logged and reviewed on a regular cadence.
Standards you can verify.
Our certifications are independently assessed and maintained – giving compliance, legal, and procurement teams the documented evidence they need.
ISO 27001
International standard for information security management systems. Independently certified – covering confidentiality, integrity, and availability of information assets across the entire organisation.GDPR / UK GDPR
Full compliance with both EU and UK General Data Protection Regulation. Lawful basis for processing, data subject rights, and privacy-by-design principles embedded across operations and product.AWS AES-256 Encryption
Data stored on AWS S3 with Server Side Encryption enabled. 256-bit AES applied to all buckets and volumes. Encryption keys managed with a regularly rotated root key for sustained cryptographic integrity.Privacy by Design
Privacy embedded at architecture level from day one. Consent-first recording, data minimisation, user-controlled retention, and invite-only meeting capture are core product behaviours.Your data stays yours. Full stop.
We don't use your data to train general-purpose models, share it with third parties, or retain it beyond the purposes of delivering our services to you – always in line with agreed terms and applicable regulations.
Customer call data is never used to train Aveni's AI models
Third-party AI providers are never trained on your data
Aveni only records meetings it is explicitly invited to join
You control what is recorded, what is shared, and when it is deleted
Conversations are private and accessible only to authorised users
Data is processed solely to deliver our services – nothing else
We understand that your discussions often involve highly sensitive and confidential data. That's why privacy and security are not policy documents at Aveni – they're design requirements embedded into every product decision we make.
Your data. Protected.
For technical reviewers, infosec teams, and procurement – the specifics of how we protect your data and environment.
AES-256 at Rest & in Transit | aws-s3-sse
AWS S3 Server Side Encryption enabled across all data buckets and machine volumes. 256-bit AES applied end-to-end. Root encryption key rotated regularly – removing long-term static exposure.
2FA & Role-Based Access | rbac
Two-factor authentication enforced across all accounts. Internal admin access requires explicit security approval and is restricted to job-function necessity. All events logged and reviewed.
MDM & Endpoint Controls | jamf
All employee devices enrolled in mobile device management. Hard-drive encryption enforced by default. Anti-malware installed, maintained and centrally managed across the entire device fleet.
Vetted, Bound Employees | bg-check
Clean cases flow through. Higher- risk cases route to reviewers with evidence pre-gathered. Scale assurance without scaling headcount.
Isolated Production Environments | aws-vpc
Customer data provisioned in isolated AWS production projects. Complete logical separation between organisations. No data from one customer is accessible to another.
Controlled Retention & Deletion | 30d-trash
Users control their own data lifecycle. Conversations automatically purged after 30 days in trash. Manual deletion is honoured immediately. No data persists beyond agreed retention terms.
Security & trust – answered.
The questions we hear most from compliance leads, infosec teams, and procurement during due diligence.
Are customer calls or transcriptions used to train Aveni's AI models?
No. Customer and call data is never used to train Aveni's models, and never passed to a third-party AI provider for training either. That is applied as a technical control, not just a contractual promise — your data is processed solely to deliver the service to you.
How is data encrypted and where is it stored?
In transit over modern TLS, and at rest with 256-bit AES. Data is held on AWS with Server Side Encryption enabled across every bucket and machine volume, and the root encryption key is rotated regularly so there is no long-term static exposure.
Who can access call recordings and transcripts?
Only the authorised users in your own organisation. Each customer is provisioned in an isolated AWS production project with complete logical separation, so no data from one organisation is reachable from another. Internal admin access requires explicit security approval, is restricted to job-function necessity, is protected by enforced 2FA, and every event is logged and reviewed.
How does Aveni help meet FCA and Consumer Duty requirements?
By giving you 100% coverage of calls and documents rather than a sample, with clear traceability and documentation at every stage. That supports Consumer Duty, suitability, conduct and customer vulnerability obligations, and it is audit-ready by design — for internal governance or external regulatory review.
What happens to our data when we delete it?
You control your own data lifecycle. Manual deletion is honoured immediately, conversations in trash are purged automatically after 30 days, and no data persists beyond the retention terms you have agreed.
How does Aveni control which meetings the AI joins?
Aveni only records meetings it has been explicitly invited to join — capture is invite-only and consent-first by design. You control what is recorded, what is shared, and when it is deleted.
Can we review security documentation for due diligence?
Yes. We are ISO 27001 certified and GDPR / UK GDPR compliant, and we share the supporting documentation with compliance, infosec and procurement teams as part of due diligence. Contact us and we will route the request to the right team.
Work with confidence.
Trusted by financial institutions who cannot afford to compromise. Evaluating Aveni? We're ready to support your security review – with documentation, direct answers, and a team that understands your regulatory environment.