Skip to main content

Our Commitment

We know that our customers have the highest requirements for data protection and information security – and we take this responsibility very seriously. For us, security is not a one-off project but a continuous process. We combine internationally recognized standards, technical excellence, and regular audits to provide our customers with a platform they can trust at any time.

Certified Information Security

avency GmbH, the company behind VARIOS AI, is certified according to ISO/IEC 27001 and ISO 9001. Our preferred hosting partner also meets the highest security and quality standards. Detailed information about the security measures can be found here: https://docs.hetzner.com/general/others/certificates

Secure Software Development

Security is an integral part of the development process:
  • Secure coding guidelines based on established standards
  • Regular penetration tests by independent security experts
  • OWASP Top 10 and other best practices as binding benchmarks
  • Automated CVE scans with every deployment
This ensures that security aspects are not added later but are integrated into the software from the very beginning.

Data Encryption

All chats and uploaded documents in VARIOS AI are encrypted – both at rest and in transit. This ensures that sensitive information is protected in the best possible way at all times.
VARIOS AI encrypts all data at rest with AES-256 in Galois/Counter Mode (AES-256-GCM) with a 96-bit initialization vector length (IV). This internationally recognized standard combines strong encryption with integrated integrity checking, thereby ensuring both confidentiality and tamper protection. It complies with the recommendations of the BSI Technical Guideline TR-02102 for maximum security.
The private key (RSA key) can be chosen by the user.

Flexible Hosting Options

In addition to our cloud variant, VARIOS AI also offers the option of on-premise hosting. This allows particularly security-critical organizations to operate the platform entirely within their own infrastructure – in compliance with internal compliance and security policies. With the inclusion of a local model, VARIOS AI can be operated without any connection to the internet.