Avantwerk CRM — Security Statement

Version 2.1 · effective date to be set on publication

1. Shared responsibility

Layer Responsibility
Avantwerk configuration, its own access grants, restricted administrative access, tracked-source change control, incident handling and escalation
Hosted-platform supplier identified in the DPA hosted platform, infrastructure and measures described in its current DPA and security materials
Customer user lifecycle, devices and credentials, least privilege, instructions, lawful use, integrations and required exports

Optional and configuration-specific controls are recorded in the Order and DPA Annex A. This document does not claim every control is available or enabled for every Customer.

2. Avantwerk-controlled measures

Avantwerk uses named accounts and roles where supported, protects credentials, limits administrative access to service need, documents changes in tracked sources, verifies generated surfaces and maintains supplier escalation.

Before publication, separate evidence is required for MFA enforcement, access revocation, authorised-person confidentiality, incident records, actual logs and retention, and backups outside the hosted platform.

3. Confirmed hosted-platform supplier measures

The current DPA of the supplier identified in the data-processing agreement assigns it, among other things:

  • AES-256 CBC for personal data at rest and TLS 1.2+ in transit;
  • roles and subaccount authentication, access control and role-based restrictions;
  • supplier endpoint protection, uptime monitoring and action logging;
  • AWS and Google Cloud managed infrastructure and five-minute-granularity point-in-time recovery; and
  • third-party vulnerability scans or external-infrastructure audits and annual third-party penetration testing of supplier systems.

The supplier's current security documentation also describes regular backups, seven days of database backups, daily local-region backup, execution monitoring and WORM/access protections. Customers cannot initiate failover; supplier teams manage recovery.

These are commitments and practices of the supplier identified in the DPA, not Bennovate’s own certifications or controls. They are not extended to every integration, device, item of data or service without evidence.

4. Claims not made

Bennovate does not attribute the hosted-platform supplier's or its downstream providers' certifications to itself. This document does not promise “full encryption” across every layer, Avantwerk-operated 24/7 monitoring or penetration testing, guaranteed failover, recovery time, backup period, uptime or deletion unsupported by the supplier.

Marketplace integrations, AI, telephony, email, recording and transcription have separate flows and must be identified in the Order.

5. Incidents

Suspected incidents should be reported to [email protected] or [email protected] with available evidence. Avantwerk classifies the event, contains components under its control, involves the supplier and preserves relevant records.

As processor, Avantwerk notifies the Customer without undue delay after awareness and provides information in phases. The hosted-platform supplier's notification limit is disclosed in the DPA; Avantwerk therefore does not promise an absolute 12-hour deadline dependent on earlier supplier information.

6. Customer duties

The Customer uses unique accounts, removes departing personnel, protects devices and credentials, enables available MFA, applies least privilege, reviews integrations, maintains needed exports and reports compromise. Special-category, criminal-offence or confidential data must not enter AI or other features without documented assessment and safeguards.

7. Review

Sources for the hosted-platform supplier identified in the DPA were checked on 28 August 2026: its DPA, subprocessor register and security overview. Review is required after changes to platform, supplier, configuration or those sources.

Avantwerk CRM contractual content · Bennovate sp. z o.o. · [email protected]