Back to Trust Center

    Security

    Averisys Analytics is committed to securing Azure architecture. The platform uses Microsoft Entra ID, Azure RBAC, and managed identities for service authentication. The team stores secrets in Azure Key Vault, not in source code or local config. It uses private endpoints and restricts public network access where supported. It monitors policy drift with Azure Policy and Microsoft Defender for Cloud. Azure OpenAI supports private networking, Azure RBAC, managed identities, and Policy-based monitoring. Microsoft also states that customers do not access the underlying host or OS for Azure OpenAI.

    Averisys Analytics protects encryption keys and service secrets in Azure Key Vault. The firm enables soft delete, purge protection, and rotation for critical keys. It uses least privilege, MFA, and JIT elevation for privileged access. Azure guidance recommends managed identities, Azure RBAC, private endpoints, and disabled public access for Key Vault.

    How Averisys Analytics applies this in practice

    Averisys Analytics treats customer data as material held in trust. Access follows the least privilege principle: staff and services receive only the access a specific task requires, and that access is reviewed and removed when the task ends. Data is encrypted in transit and at rest, administrative activity is logged, and separate environments keep testing work away from production records. Where analysis can be performed on aggregated or de-identified data, that is the default rather than the exception.

    Practices are documented so a customer's own security, privacy, or procurement reviewer can verify them instead of taking a claim at face value. Averisys Analytics answers security questionnaires, explains how data flows through the platform, and states plainly what it does and does not do with customer information. Subprocessors are limited to those needed to operate the service, and each is selected against the same expectations applied internally.

    Policies change as the platform changes. When a new capability handles data differently, documentation is updated alongside it, and customers with an active agreement are notified of material changes. Questions about a specific requirement, contract term, or regional obligation can be sent to support@averisysanalytics.com.

    More Trust Center topics