Overview
Avistar.AI discovers and scores machine identities such as API keys, service accounts, OAuth tokens, and secrets across cloud, SaaS, and code environments, then turns that exposure into a quantified financial risk score for underwriters. Because Avistar scans the identity layer, it holds metadata about credentials, never the credential values themselves. This trust center documents the controls, policies, and third parties behind that commitment, and is kept current as our SOC 2 audit progresses.
Compliance
Compliance frameworks Avistar currently meets or is working toward to uphold their security and privacy commitments.


Resource library
Our security, compliance, and policy documentation, including audit reports.
Controls
Our security program is built on a complete set of controls that govern how we safeguard data and manage risk.
- Architecture Diagram
- Platform Availability Monitoring
- Platform Availability Alerts
- Asset Inventory
- Data Deletion
- Compliance Monitoring
- Application Authentication
- User Segregation
- Role-based Access
- Password Manager
- Onboarding Checklist
- Offboarding Checklist
- Confidential Data Deletion
- Asset Management Policy
- Information Security Roles and Responsibilities Policy
Subprocessors
Trusted third parties that support our services and may process customer data as part of their function.