Security at Avid
Avid is the Fundraising Operating System for nonprofit organizations. The data our customers trust us with is sensitive, and we treat it that way.
Certifications and frameworks
We maintain SOC 2 Type II certification and TX-RAMP Level 1 certification. Our security program is aligned to the NIST Cybersecurity Framework and NIST SP 800-53. Real-time compliance monitoring is available at trust.avidai.com.
Hosting and infrastructure
Avid runs exclusively on the infrastructure of a leading enterprise cloud provider, in US-based regions. Regional data location options are available for Australia, Canada, and the EU where applicable. Our system status is published at status.avidai.com.
Data isolation
Avid is multi-tenant with strict logical data isolation. Each customer’s data is stored in a dedicated, isolated data environment. Customer data is never commingled.
Encryption
Data is encrypted at rest and in transit using current industry standards. Encryption keys used to protect customer data are not accessible to our infrastructure provider.
Application security
We operate an enterprise-grade web application firewall with protections addressing the OWASP Top 10. External vulnerability scanning is performed on an ongoing basis, and static and dynamic application security testing are built into our development lifecycle. Source code is maintained in secure version control systems.
Critical and high vulnerabilities are remediated within defined SLA windows; average remediation is under 48 hours.
Identity and access
Single sign-on is supported via SAML and OAuth. Multi-factor authentication is enforced for administrative access.
Logging and monitoring
Infrastructure logs are retained in our cloud logging platform. Application-level audit logs are retained for a minimum of 12 months.
Incident response
We maintain a documented incident response plan and 24×7 incident response capability. We carry cyber liability insurance.
Personnel security
Background checks and security awareness training are required for all staff.
Payments
Avid does not receive, process, or store cardholder data. Billing for Avid subscriptions is handled through a PCI DSS compliant third-party payment provider using a hosted payment interface. The Avid platform is out of scope for PCI DSS.
Privacy
Our privacy policy is available at app.avidai.com/privacy_policy.
Reporting a vulnerability
If you believe you have found a security vulnerability in Avid, we want to hear about it.