Data Protection & Encryption
How is data encrypted in transit and at rest?
How is data encrypted in transit and at rest?
Do you ever use customer data to train models or analytics?
Do you ever use customer data to train models or analytics?
What retention, deletion and export controls exist?
What retention, deletion and export controls exist?
Deployment & Infrastructure
Can I deploy ABV in a single-tenant environment?
Can I deploy ABV in a single-tenant environment?
How is tenant isolation enforced?
How is tenant isolation enforced?
Can customers pin data to specific regions?
Can customers pin data to specific regions?
Where is ABV hosted and how is the perimeter protected?
Where is ABV hosted and how is the perimeter protected?
Compliance & Certifications
Which audits and attestations are in place?
Which audits and attestations are in place?
How often are third-party pen tests performed, and are results shareable?
How often are third-party pen tests performed, and are results shareable?
Identity & Access Management
Which authentication options are supported?
Which authentication options are supported?
How is least-privilege enforced?
How is least-privilege enforced?
Application Security & SDLC
What secure-coding and testing practices are in place?
What secure-coding and testing practices are in place?
Incident Response & Business Continuity
What is the incident-response process?
What is the incident-response process?
Vulnerability & Pen-Testing
How is the disclosure program run?
How is the disclosure program run?
Can customers run their own pen-tests?
Can customers run their own pen-tests?
Sub-processors & Third-Party Risk
Which sub-processors have access to customer data?
Which sub-processors have access to customer data?
AI / LLM-Specific Concerns
Does ABV store PII or trade secrets from prompts?
Does ABV store PII or trade secrets from prompts?
Can long-term retention be disabled?
Can long-term retention be disabled?
Is prompt/trace data ever used for benchmarking or training?
Is prompt/trace data ever used for benchmarking or training?
Governance, People & Culture
How are employees vetted and trained?
How are employees vetted and trained?
Who owns security inside ABV?
Who owns security inside ABV?