Security at Avid

Avid is the Fundraising Operating System for nonprofit organizations. The data our customers trust us with is sensitive, and we treat it that way.

Certifications and frameworks

We maintain SOC 2 Type II certification and TX-RAMP Level 1 certification. Our security program is aligned to the NIST Cybersecurity Framework and NIST SP 800-53. Real-time compliance monitoring is available at trust.avidai.com.

Hosting and infrastructure

Avid runs exclusively on the infrastructure of a leading enterprise cloud provider, in US-based regions. Regional data location options are available for Australia, Canada, and the EU where applicable. Our system status is published at status.avidai.com.

Data isolation

Avid is multi-tenant with strict logical data isolation. Each customer’s data is stored in a dedicated, isolated data environment. Customer data is never commingled.

Encryption

Data is encrypted at rest and in transit using current industry standards. Encryption keys used to protect customer data are not accessible to our infrastructure provider.

Application security

We operate an enterprise-grade web application firewall with protections addressing the OWASP Top 10. External vulnerability scanning is performed on an ongoing basis, and static and dynamic application security testing are built into our development lifecycle. Source code is maintained in secure version control systems.

Critical and high vulnerabilities are remediated within defined SLA windows; average remediation is under 48 hours.

Identity and access

Single sign-on is supported via SAML and OAuth. Multi-factor authentication is enforced for administrative access.

Logging and monitoring

Infrastructure logs are retained in our cloud logging platform. Application-level audit logs are retained for a minimum of 12 months.

Incident response

We maintain a documented incident response plan and 24×7 incident response capability. We carry cyber liability insurance.

Personnel security

Background checks and security awareness training are required for all staff.

Payments

Avid does not receive, process, or store cardholder data. Billing for Avid subscriptions is handled through a PCI DSS compliant third-party payment provider using a hosted payment interface. The Avid platform is out of scope for PCI DSS.

Privacy

Our privacy policy is available at app.avidai.com/privacy_policy.

Reporting a vulnerability

If you believe you have found a security vulnerability in Avid, we want to hear about it.