ISO/IEC 27001:2022
Certified information security management
Avion operates an independently certified information security management system covering the policies, processes and controls used to manage information-security risk.
Avalon combines certified identity, dedicated-tenant architecture, governed access and end-to-end auditability. It is developed and operated by Avion under independently assessed security and control frameworks.
Certified information security management
Avion operates an independently certified information security management system covering the policies, processes and controls used to manage information-security risk.
Controls assessed over time
Avion maintains a SOC 2 Type 2 attestation covering the design and operating effectiveness of relevant controls across security, availability and confidentiality.
Certified identity provider
Avalon Identity is independently certified by the OpenID Foundation across all four submitted conformance profiles, providing a standards-aligned identity foundation for Avalon and connected applications.
Avalon is deployed in a dedicated Azure tenant for each customer, creating a clear boundary around applications, identity, data and operational controls.
This supports stronger isolation, customer-specific configuration and clearer accountability than a shared multi-tenant application environment.
Avalon can be deployed in an agreed Azure region to support customer requirements for performance, resilience and data residency, subject to service availability and contractual agreement.
Data is protected using encryption in transit and at rest, supported by managed key controls, access restrictions and monitored administrative processes.
Avalon Identity provides centralised authentication and access control across Avalon and connected applications.
Access to Avalon is governed through defined identities, roles and permissions.
Separate administrative and operational duties
Apply consistent controls across connected solutions
Review access and administrative activity
Maintain evidence for internal and external assurance
Access requirements can be configured around the customer's organisation, operating model and governance obligations.
Avalon records significant user, workflow, identity and administrative activity to support operational oversight, investigation and assurance.
Structured records help teams understand who performed an action, what changed, when it occurred, which record or workflow was involved and how related events are connected.
Within Avalon Identity, authentication, token, session, passkey, consent, signing-key and administrative events are captured through a structured, tamper-evident audit trail.
Controlled administrative access, role separation, multi-factor authentication and periodic access review.
Security and operational monitoring supported by documented triage, escalation, investigation and notification processes.
Structured assessment, remediation and controlled deployment of application and infrastructure changes.
Managed backups, recovery procedures and service-continuity planning appropriate to the contracted service.
Assessment and oversight of relevant cloud, technology and service providers.
Security considerations incorporated into architecture, development, testing, release and ongoing maintenance.
Qualified customers, auditors and security reviewers can request relevant assurance material, subject to confidentiality requirements.
Tell us about your organisation, regulatory environment, identity requirements and deployment constraints. We'll help you evaluate the relevant Avalon architecture, controls and assurance evidence.
Talk to us