Trust center
What your vendor management, compliance and information security teams will ask, answered in one place. Documents marked NDA are available on request.
SOC 2 Type II
Audited annually against the security, availability and confidentiality criteria. The report covers the platform, Ava and the appraiser network.
Request the report (NDA) →AIR compliance
Ordering is separated from production. Loan production staff cannot select, contact or influence the appraiser, and the order record shows who did what and when.
AIR summary →Reconsideration of value
ROV requests are submitted, routed to the appraiser and answered in the platform. The request, the response and the timeline stay on the file.
UCDP and EAD
Submission to both GSE portals and to FHA, with the response written back to the loan.
SSO and SAML
Single sign-on with your identity provider, role-based access, and per-user audit of every action.
Audit logs
Every order event, every review finding, every override and every payment is logged with actor, timestamp and reason, exportable for examination.
Data retention
Reports and order records retained for the period your policy requires and deleted on schedule.
Retention schedule →Third-party risk packet
The documents your vendor management team needs in one packet: SOC 2 report, policies, insurance certificates, business continuity summary, subprocessor list.
Request the packet →Ava governance
Reasoning on every finding, versioned rules, scheduled model releases with notes, human override on every finding. Model documentation for your model risk review on request.
About Ava →Status
99.9%
uptime, trailing twelve months
Incident history and subscribe options on the full status page.
Subprocessors and data
Payments are processed through Stripe.
Send us your security questionnaire.
We answer it with the packet, and a call with whoever needs to ask the follow-ups.