ALVAO Trust Center

Transparency, security, and reliability you can verify. ALVAO delivers secure ITSM and ITAM solutions with a strong focus on data protection, regulatory compliance, and high service availability.

Compliance

Product Security

Data Privacy

Reliability & Availability

Subprocessors

Data Residency

Data Portability & Exit

AI Governance

Legal & Regulatory

Frequently asked questions

Yes. ALVAO is GDPR compliant. Please see our Privacy Policy for full details on how we process personal data.

Yes. Selected policies, reports, and summaries are available under NDA or upon justified request to our contact.

Third parties used by ALVAO are assessed before onboarding and periodically reviewed for security and business continuity concerns. The program takes into account the type of access, classification of data being accessed, controls necessary to protect data, and legal/regulatory requirements. Confidentiality and information security requirements are included in third party agreements. We do not provide documentation on our third parties due to NDA restrictions.

Yes. Customers can perform internal vulnerability scans of their own ALVAO ITSM environment upon prior notice.

Yes. All customer data is encrypted in transit (TLS 1.2+) and at rest using AES-256 via Microsoft Azure.

Yes. Data is securely erased and storage wiped out by Microsoft Azure in line with their data protection procedures.

Contact & Responsible Disclosure

Questions about security, compliance, or reporting a vulnerability? We're here.

Security incidents

Report a vulnerability or security issue. Please include a step-by-step proof of concept (PoC) demonstrating your findings so we can verify their validity.

security@alvao.com

Compliance questions

Inquiries about certifications, audits, or compliance documentation.

infosec@alvao.com