AVATALK← Back to site

AVATALK Information Security Policy

Effective Date: August 27, 2026

Introduction

AVATALK is committed to ensuring the confidentiality, integrity, and availability of our customers’ data. This Information Security Policy outlines the measures we implement to protect systems, applications, and data. It applies to all employees, contractors, vendors, and third-party providers who have access to AVATALK infrastructure or information.

Access Control

We restrict system and data access to authorized individuals based on role and responsibility. Our controls include:

  •       User Authentication: All accounts require secure credentials (username and password).
  •       Password Policy: Passwords must be strong and are subject to periodic updates.
  •       Account Management: Access rights are provisioned by our technical team based on the principle of least privilege.
  •       Multi-Factor Authentication: MFA is used for sensitive systems to add an additional layer of protection.

Data Storage and Media Processing

AVATALK uses contracted cloud infrastructure, storage, database, real-time media, AI inference, voice, and GPU processing services to operate the platform. Depending on availability, performance, and legal requirements, data may be processed in geographically distributed facilities.

We apply access controls and encryption in transit and at rest where supported, limit providers to the data needed to perform their services, and evaluate relevant security and privacy safeguards as part of our vendor-management process.

Data Protection

We take measures to protect the confidentiality, integrity, and availability of our customers’ data. The data protection measures include the following:

  •       Encryption: We use encryption technologies to protect sensitive data in transit and at rest.
  •       Data Backup: We regularly back up our data to prevent data loss due to hardware failures or disasters.
  •       Data Retention: We retain data only as long as necessary and in accordance with relevant laws, regulations, and industry standards.
  •       Data Destruction: We dispose of data securely and in accordance with relevant laws, regulations, and industry standards.

Incident Management

We have established an incident management process to detect, investigate, and respond to security incidents. The incident management process includes the following:

  •       Incident Response Plan: We have developed a comprehensive incident response plan that outlines the procedures to be followed in the event of a security incident.
  •       Incident Reporting: All employees, contractors, vendors, and third-party providers are required to report security incidents immediately to our IT department.
  •       Incident Investigation: We investigate security incidents promptly to determine the cause and scope of the incident.
  •       Incident Communication: We communicate with affected parties, such as customers and law enforcement, as necessary and in accordance with relevant laws, regulations, and industry standards.

Compliance

We comply with relevant laws, regulations, and industry standards related to information security. Our compliance approach includes:

  •       Internal Policy Adherence: While AVATALK, Inc. does not currently hold SOC 2 certification directly, we follow internal information security policies aligned with best practices and evaluate vendor compliance as part of our security controls.
  •       Third-Party Compliance: We assess relevant security, privacy, and contractual safeguards before using third-party service providers and periodically review providers based on the nature and sensitivity of the data they process. Provider certifications support, but do not replace, AVATALK's own security responsibilities.
  •       Audit and Assessment: We periodically review our technical and administrative security controls to ensure effectiveness and consistency with industry standards.

Conclusion

AVATALK takes information security seriously and is committed to ensuring that our product is secure and reliable. We implement robust information security measures, including access control, data protection, incident management, and compliance. All employees, contractors, vendors, and third-party providers are required to comply with our information security policies and procedures.

AVATALK
Privacy PolicyTerms And ConditionsCookie PolicyEthical Use of Synthetic MediaSecurity PolicyEnterprise SaaS Agreement

© 2026 AVATALK, Inc. All rights reserved.