What we collect
- Account information — name, email, company, title, and optional phone.
- Flow metadata only — NetFlow, IPFIX, and sFlow fields such as IPs, ports, protocol, volume, and timestamps.
What we do not collect
- No audio, video, or other media content. We do not inspect streams.
- No agents on AV endpoints (encoders, decoders, displays).
- No packet payloads. Metadata only.
How the product works
AVoIP Guard ingests export metadata from the switches and routers you already run — Netgear, Meraki, Fortinet, UniFi, and similar platforms that speak NetFlow, IPFIX, or sFlow. We baseline that metadata and flag AV-relevant risk. Your Dante, NDI, and ST 2110 streams are never mirrored, decoded, or stored.
Where things run
- Marketing site (avoipguard.com) is hosted in the United States.
- Application runs at app.avoipguard.com, hosted in the United States on infrastructure we control.
Subprocessors we use today
Named services in production now; This list will expand as we grow.
| Provider | Role | When |
|---|---|---|
| Groq / model providers | AI triage features in the application | When those features are enabled |
| Stripe | Payment processing | Only if and when a paid plan is purchased. Beta signup does not require a credit card. |
| Transactional email provider | Account and beta emails (password setup, support replies) | When we send transactional mail |
Vulnerability reporting
Email security@avoipguard.com with enough detail for us to reproduce the issue (affected URL or endpoint, steps, and impact). We will acknowledge reports. Do not run destructive testing against production without written permission. We do not have a paid bug bounty program yet.
Compliance status
We have not completed a SOC 2 audit. When we start or finish one, this page will be updated. Paid and enterprise customers can review our Data Processing Addendum.
Contact
AVoIP Guard LLC
United States