- Read-only ingestion. Connectors pull from your sources; nothing is ever written back to your systems.
- No training on your data. Customer data is never used to train models — by Pavo or by any model provider. External LLM providers operate under zero-data-retention (ZDR) terms.
- Everything disclosed. Every component and sub-processor is documented; optional integrations are individually gated per instance and disabled unless you enable them — in both deployment models.
Certifications & assurance
Data handling & lifecycle
All customer data is classified Confidential by default under Pavo’s data classification policy (Public / Internal / Confidential / Restricted; unlabelled data defaults to Confidential). Encryption is AES-256 at rest via cloud KMS and TLS 1.2+ in transit; customer-managed keys (CMEK) are available in both deployment models.Identity & access
- SSO through your identity provider (OIDC); least-privilege access with audit logging throughout.
- MFA mandatory for all production and administrative access; access reviews at least annually; access revoked immediately on termination.
- No standing engineer access to customer environments — support access is time-boxed, authorized, and audited.
Network & egress
- No public data endpoints; network isolation throughout.
- Agent-executed code runs in a sandbox behind a default-deny egress allowlist proxy. The allowlist is tiered: a minimum tier (open-source package registries needed for data/ML work), an opt-in tier enabled only with your approval, and customer-specific entries for your own cloud endpoints. The full allowlist is available on request and agreed per deployment.
Platform hardening
- Signed images verified at admission; SSH disabled by default.
- Monthly infrastructure and application vulnerability scans plus continuous dependency scanning; patch SLAs: Critical 24h · High 7d · Medium 30d · Low 90d.
Incident response & resilience
- Documented incident response with a defined escalation chain and a named CISO and Data Protection Officer. Breach notification without undue delay — target within 72 hours of confirmation, aligned with the GDPR supervisory standard. Data subject requests answered within one month.
- Business continuity: RTO 4 hours, RPO 1 hour. Backups at least weekly plus database snapshots, multi-AZ within a single region; restoration tested at least annually.
Requests
The SOC 2 Type II report, ISO/IEC 27001 certificate, penetration test executive summary, DPA and sub-processor annex, full reference architecture for VPC deployments, egress allowlist, and any policy from the ISMS set are available on request: Srijan Saket — CISO & Data Protection Officer · srijan@pavoai.comNext steps
Sub-processors
Every third party, the data it processes, and how it runs per deployment.
Deployment options
Compare Pavo Cloud, Customer VPC, and Hardened VPC side by side.