Snapshot 50181
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security at Avid Avid is the Fundraising Operating System for nonprofit organizations. The data our customers trust us with is sensitive, and we treat it that way. Certifications and frameworks We maintain SOC 2 Type II certification and TX-RAMP Level 1 certification. Our security program is aligned to the NIST Cybersecurity Framework and NIST SP 800-53. Real-time compliance monitoring is available at trust.avidai.com. Hosting and infrastructure Avid runs exclusively on the infrastructure of a leading enterprise cloud provider, in US-based regions. Regional data location options are available for Australia, Canada, and the EU where applicable. Our system status is published at status.avidai.com. Data isolation Avid is multi-tenant with strict logical data isolation. Each customer’s data is stored in a dedicated, isolated data environment. Customer data is never commingled. Encryption Data is encrypted at rest and in transit using current industry standards. Encryption keys used to protect customer data are not accessible to our infrastructure provider. Application security We operate an enterprise-grade web application firewall with protections addressing the OWASP Top 10. External vulnerability scanning is performed on an ongoing basis, and static and dynamic application security testing are built into our development lifecycle. Source code is maintained in secure version control systems. Critical and high vulnerabilities are remediated within defined SLA windows; average remediation is under 48 hours. Identity and access Single sign-on is supported via SAML and OAuth. Multi-factor authentication is enforced for administrative access. Logging and monitoring Infrastructure logs are retained in our cloud logging platform. Application-level audit logs are retained for a minimum of 12 months. Incident response We maintain a documented incident response plan and 24×7 incident response capability. We carry cyber liability insurance. Personnel security Background checks and security awareness training are required for all staff. Payments Avid does not receive, process, or store cardholder data. Billing for Avid subscriptions is handled through a PCI DSS compliant third-party payment provider using a hosted payment interface. The Avid platform is out of scope for PCI DSS. Privacy Our privacy policy is available at app.avidai.com/privacy_policy. Reporting a vulnerability If you believe you have found a security vulnerability in Avid, we want to hear about it.