ALVAO has processes in place to detect, respond to, and manage Security Incidents and Personal Data Breaches. Customers are informed of relevant incidents in accordance with contractual obligations and applicable regulations.
Specifically, under the Data Processing Addendum (DPA Art. 11.3), if the Provider (ALVAO) becomes aware of a breach of security leading to the accidental or unauthorized loss, destruction, alteration, unauthorized disclosure of, or access to Customer Data, Professional Services Data, or Personal Data processed by the Provider (each a “Security Incident”), the Provider will, without undue delay and in any event within seventy-two (72) hours after becoming aware of the Security Incident:
notify the Customer of the Security Incident;
investigate the Security Incident and provide the Customer with detailed information about the Security Incident; and
take reasonable measures to mitigate the effects and minimize any damage resulting from the Security Incident.
Report a vulnerability or security issue: infosec@alvao.com. Please include a step-by-step proof of concept (PoC) demonstrating your findings so we can verify their validity.