# Compliance & certifications

> ISO 27001, SOC 2 Type II, PCI DSS and data-protection laws in every country we operate in.

Source: https://docs.avenlith.com/en/compliance  
Category: Security & compliance  
Last updated: 2026-09-22

## Certifications

| Standard | Scope | Renewed |
| --- | --- | --- |
| ISO/IEC 27001:2022 | All regions and operations | Annually |
| SOC 2 Type II | Cloud, Shield, managed services | Annually |
| PCI DSS 4.0 (Level 1) | Payment-ready infrastructure | Annually |
| Uptime Institute Tier III | MOW1, IST1, FRA1 facilities | Per facility |

Reports are available under NDA in **Support → Compliance documents**.

## Data protection

- **GDPR** — data processing agreement (DPA) and standard contractual clauses for EU customers
- **KVKK** — Turkish personal data stays in IST1 or AYT1 on request
- **152-FZ** — Russian personal data is stored in MOW1, MOW2 or LED1

> **Note:** > Avenlith staff never access customer data without a support ticket and your explicit consent. Every access is logged and reviewed monthly.

## Penetration testing

You may test your own resources without prior notice. Tests against shared infrastructure or Shield require written approval.
