If your security team, insurer, or prime contractor is evaluating AveLu as a vendor, this page is for you. Here is how we run our own security, what we commit to in writing, and what we will never promise.
How we run our own house
Identity & access
Phishing-resistant MFA on every account, least-privilege access to client environments, unique per-client credentials, and access reviews on a fixed schedule.
Client environment handling
Documented change control, no standing admin access where delegated access works, and audit logging enabled in every environment we manage.
Frameworks we align to
Our practices map to CIS Controls and NIST CSF; our AI governance work aligns to the NIST AI Risk Management Framework. We speak the same language your auditors do.
Documentation available on request: shared responsibility matrix · security questionnaire / DDQ responses · reference architecture · insurance certificates. Email andres@avelutech.com and we respond within one business day.
Support, Defined
Our SLA in plain sight.
Severity & response commitments
P1 Critical (outage or active security incident): 1 hour response · 24/7 emergency line
P2 High (department down): 2 business hours · 24/7 emergency line
P3 Normal (one user affected): 4 business hours
P4 Low (how-to questions and minor requests): 1 business day
Business hours: 8am to 6pm ET, Monday through Friday · after-hours non-emergency work at 1.5× rate, $220 minimum
What we promise and what we refuse to promise
We commit to response times in writing; resolution times are estimates, because honest ones always are
Every engagement ships with a shared responsibility matrix: who owns what, signed
We implement and document; accredited auditors and regulators certify. We will never sell you a “compliance guarantee”
If you decline a control we recommend, we document it and move on. No pressure, and no surprises later
Nothing in our agreements is “unlimited.” Defined scope is what makes fixed fees honest