ISO 27001 Certified Security Management ISO 27001 Certified Security Management ISO 27001
SOC 2 Type 2 Attested SOC 2 Type 2 Attested SOC 2
OpenID Connect Certified Identity Provider OpenID Connect Certified Identity Provider OpenID
Security & Trust

Trust engineered into every layer.

Avalon combines certified identity, dedicated-tenant architecture, governed access and end-to-end auditability. It is developed and operated by Avion under independently assessed security and control frameworks.

Independent assurance

Evidence your security team can verify.

Certified

ISO/IEC 27001:2022

Certified information security management

Avion operates an independently certified information security management system covering the policies, processes and controls used to manage information-security risk.

View certification evidence
Attested

SOC 2 Type 2

Controls assessed over time

Avion maintains a SOC 2 Type 2 attestation covering the design and operating effectiveness of relevant controls across security, availability and confidentiality.

Request the SOC 2 report
Certified

OpenID Connect

Certified identity provider

Avalon Identity is independently certified by the OpenID Foundation across all four submitted conformance profiles, providing a standards-aligned identity foundation for Avalon and connected applications.

Explore Avalon Identity
Architecture

Dedicated by design.

A dedicated tenant for every customer

Avalon is deployed in a dedicated Azure tenant for each customer, creating a clear boundary around applications, identity, data and operational controls.

This supports stronger isolation, customer-specific configuration and clearer accountability than a shared multi-tenant application environment.

Regional deployment

Avalon can be deployed in an agreed Azure region to support customer requirements for performance, resilience and data residency, subject to service availability and contractual agreement.

Protection in transit and at rest

Data is protected using encryption in transit and at rest, supported by managed key controls, access restrictions and monitored administrative processes.

Avalon Identity

Identity is the trust foundation.

Avalon Identity provides centralised authentication and access control across Avalon and connected applications.

OpenID Connect-certified identity FIDO2 passkeys Multi-factor authentication Secure account lifecycle Roles and permissions Hardened token management Centralised self-service Structured audit events
Explore Avalon Identity
Governed access

Access appropriate to every responsibility

Access to Avalon is governed through defined identities, roles and permissions.

  • Separate administrative and operational duties

  • Apply consistent controls across connected solutions

  • Review access and administrative activity

  • Maintain evidence for internal and external assurance

Access requirements can be configured around the customer's organisation, operating model and governance obligations.

Auditability

Understand what happened—and how.

Avalon records significant user, workflow, identity and administrative activity to support operational oversight, investigation and assurance.

Connected operational records

Structured records help teams understand who performed an action, what changed, when it occurred, which record or workflow was involved and how related events are connected.

Identity forensic readiness

Within Avalon Identity, authentication, token, session, passkey, consent, signing-key and administrative events are captured through a structured, tamper-evident audit trail.

Secure operation

Controls throughout the service lifecycle.

Access management

Controlled administrative access, role separation, multi-factor authentication and periodic access review.

Monitoring and incident response

Security and operational monitoring supported by documented triage, escalation, investigation and notification processes.

Vulnerability and change management

Structured assessment, remediation and controlled deployment of application and infrastructure changes.

Resilience and recovery

Managed backups, recovery procedures and service-continuity planning appropriate to the contracted service.

Supplier governance

Assessment and oversight of relevant cloud, technology and service providers.

Secure development

Security considerations incorporated into architecture, development, testing, release and ongoing maintenance.

Assurance evidence

Evidence for your review process.

Qualified customers, auditors and security reviewers can request relevant assurance material, subject to confidentiality requirements.

Get started

Start with your security and governance priorities.

Tell us about your organisation, regulatory environment, identity requirements and deployment constraints. We'll help you evaluate the relevant Avalon architecture, controls and assurance evidence.

Talk to us