Last updated: 21 August 2026
Customer data is hosted on European / US-East regions through our platform provider (Render web tier and Neon managed Postgres), with NZ/NZ clients served from the closest region available. We can confirm the exact region for any specific deploy on request — email security@aivid.com and we'll reply within one business day.
All traffic between your browser and Aivid is encrypted in transit (TLS / HTTPS only). Data at rest is encrypted at the platform database level. No production credentials, tokens, or signing keys are stored in plaintext — secrets live in the platform's secret manager. We do not claim SOC 2 Type II certification at this time; what we can document on request is the underlying platform's posture.
Access is limited to a small group of named roles — currently the founder and a short list of operators. Principle of least privilege applies: each operator only sees the data they need to do their job, and every production access is gated by SSO and produces an audit-log entry. Any access request — for support, debugging, or migration — is reviewed before being actioned. Email security@aivid.com to request a review or report an access concern.
If a security breach is confirmed to have affected customer data, we will notify the affected customers — to the contact on file — within 72 hours of confirmation. This complements but does not replace the notification clauses in our Terms of Service, which remain the binding document.
A DPA is available on request for customers who require a signed data-processing addendum alongside the standard Terms. To obtain one, email security@aivid.com. DPA terms are governed by the same jurisdiction as our Terms (New Zealand, with recognition of Australian Privacy Act where applicable).
The following subprocessors handle data on our behalf. We share this as an operational summary — for the binding list and any updates, see the Privacy Policy.
Questions about this page, our data posture, or any of the above: security@aivid.com. This page is a plain-English complement to /privacy and /terms — those two documents remain the binding legal record.