How Avian Data Inc. protects your data, infrastructure, and API interactions.
All data encrypted in transit with TLS 1.2+ and at rest with AES-256.
Zero data retention. Prompts and completions are never stored or logged.
Least-privilege access controls and regular security audits.
At Avian Data Inc. ("Avian", "we", "our", or "us"), we prioritize the security of the data you entrust to us. This page describes the technical, organizational, and operational measures we maintain to protect your information when you use our AI inference API and related services (the "Services").
All communications between your systems and Avian—including API requests, website interactions, and account management—are encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and do not support unencrypted connections.
Any data that is persisted (such as account information and billing records) is encrypted at rest using AES-256 encryption. Encryption keys are managed through dedicated key management services with strict access controls.
We do not log, store, or cache the content of your API requests (prompts) or API responses (completions). Your input and output data is processed in memory and is not written to persistent storage. Once a response is delivered, no record of the content exists in our systems.
We log only request metadata—timestamps, model selected, and token counts—for billing, rate limiting, and service monitoring. This metadata never includes prompt or completion content.
We conduct regular internal and third-party security assessments, including penetration testing and code reviews. Avian is in the process of obtaining SOC 2 Type II certification.
We comply with applicable data protection regulations, including GDPR and CCPA/CPRA, and maintain processes to respond to data subject requests. For details, see our Privacy Policy.
We maintain a documented incident response plan that covers detection, containment, investigation, and remediation of security events. In the event of a confirmed data breach, we will:
All employees complete security awareness training upon hire and on an ongoing basis. Training covers data protection, phishing awareness, secure development practices, and incident reporting. Access to production systems is logged and reviewed regularly.
If you discover a security vulnerability in our Services, we encourage responsible disclosure. Please report it to security@avian.io. We will acknowledge receipt within 48 hours and work to address confirmed vulnerabilities promptly.
For security questions or concerns, contact us: