Security · Industry
TISAX
The automotive industry's information security assessment, run under the ENX Association and recognized across German OEM and supplier supply chains.
Independent auditors and government programs worldwide assess how AvePoint protects customer data. Filter the full list by domain, scope and region.
14 certifications
Security · Industry
The automotive industry's information security assessment, run under the ENX Association and recognized across German OEM and supplier supply chains.
Security · Government & Regulated Markets
Government of Canada assurance for cloud services handling Protected B information — the classification used for sensitive federal data whose compromise could cause serious injury.
Security · Government & Regulated Markets
Japan's registration program for cloud services procured by government bodies. Listing on the ISMAP register is what makes a service eligible for public-sector purchase.

Security
AvePoint has received ISO 27001:2022 certification with respect to secure software development and maintenance process including support business functions like Infosec, IT, HR, Sales and Marketing, Project Management, Operations and Call Center.

Privacy
The scope of AvePoint Inc.'s Privacy Information Management System applies to the management, operation, and maintenance of: the people, information assets, information systems, technological platform and network infrastructure, secure software development and maintenance, services, support, and the associated processes (InfoSec, Privacy, IT, HR, Sales and Marketing, Project Management, Operations and Call Center) that enable corporate operations and development and deployment of products and services provided to customers and employees of AvePoint Inc. offered by the Firm, protecting the security and privacy (where AvePoint acts as PII Controller and Processor) of the information assets that support it.

Security · Cloud
AvePoint has received ISO 27017:2015 certification with respect to the AvePoint Cloud Security Operations, including the SaaS services/solutions provided by AvePoint to its customers.

Security · Government & Regulated Markets
AvePoint was assessed against official IRAP controls to verify its commitment to, and expertise in, protecting sensitive Australian government data. Sponsored by the Australian Transport Safety Bureau (ATSB), this assessment confirms that AvePoint adheres to the standard of cybersecurity and information security assessments for ICT systems processing or storing government information.
Security · Government & Regulated Markets
Our cloud services are fully authorized as a FedRAMP Accredited SaaS solution for use across all agencies at the Moderate impact level. We received agency-sponsored authority to operate (ATO) in April 2021.
Our SaaS solutions are currently hosted in the US East Government Azure Data Center, a FedRAMP Accredited, GCC High data center that follows the certifications and accreditations for FedRAMP High as well as the Department of Defense Impact Level 5. The service is not pursuing FedRAMP Authorization, but is managed by an operations team consisting only of US persons

Security
AvePoint has earned the System and Organization Controls (SOC) 2 Type II certification that covers AvePoint Online Services (AOS), AvePoint Migration Platform (AMP), DocAve, Compliance Guardian, Governance Automation, and Records, that collectively migrate, manage, and protect data across cloud and on-premises collaboration systems.
The SOC 2 Type II audit and attestation, conducted by an independent CPA firm, confirms that AvePoint meets the strict information security and privacy standards for the handling of highly sensitive customer data established by the American Institute of Certified Public Accountants (AICPA). Our report is issued by independent third-party auditors and covers the principles of Security, Availability, Confidentiality, and Privacy.

Security · Cloud
AvePoint is certified against the Cloud Security Alliance (CSA) Security, Trust, Assurance and Risk (STAR) Level 2 as a cloud service provider.

Privacy
AvePoint has been awarded the Data Protection Trustmark (DPTM) Certification by Infocomm Media Development Authority (IMDA) Singapore, recognising our commitment to strong and accountable data protection practices. For our customers, this certification provides added assurance that your data is managed responsibly, securely, and in alignment with government-recognised data protection standards.

Security · Government & Regulated Markets
DESC CSP Security Standard (Dubai Electronic Security Center Cloud Service Provider Security Standard).
AvePoint's Cloud Services are certified against the DESC CSP Security Standard. Compliance with this standard is required to provide cloud services to Dubai government and semi-government entities. The standard is strongly aligned with international frameworks such as ISO 27001, ISO 27002, and ISO 27027, to which AvePoint is also certified.

Security
AvePoint was assessed and certified against Cyber Essentials Plus (CE+). This is a United Kingdom (UK) Government defined methodology, which through independent testing, helps demonstrate the implementation of cyber security controls within the organization and its systems. Through rigorous assessment and verification, AvePoint demonstrates its commitment to maintaining a strong security posture through this achievement.

Security · Government & Regulated Markets
AvePoint has achieved CMMC Level 2 certification — covering all 110 practices across 14 control domains. When your data security partner holds the certification, your compliance journey gets a lot shorter. And because the Confidence Platform is also IL5 and FedRAMP High certified, you can meet stringent federal requirements with greater confidence.