Security

What we protect, and what we do not have yet.

Most agencies list certifications they do not hold. Here is the honest version: what is in place today, and what is not.

In place today

What every assistant must do

Conditions of working with us. Checked before a placement starts, and every quarter after.

Full disk encryption

BitLocker or FileVault on, verified by screenshot before day one. Without it, a stolen laptop is a stolen filing cabinet.

A managed password manager

We provide it and pay for it. No passwords in notebooks or spreadsheets, and none reused across your accounts and their personal ones.

Two-factor on everything

Every account your assistant touches, including their own email. App-based codes, not SMS.

A locked screen and a private room

Automatic lock after five minutes. No shared family computer. No co-working space with a screen facing a walkway.

Your accounts, never ours

Your assistant works inside your systems, under credentials you control. We hold no copy of your data and never ask you to move it to us.

A written offboarding checklist

When a placement ends we walk every system, remove access, and send written confirmation of what was revoked and when.

Being straight with you

What we do not have

We do not issue laptops yet. Your assistant works on their own machine. We set the standard above and verify it, but we do not own the hardware, so we cannot wipe it remotely. Agencies charging three thousand a month can. We charge less, and this is part of why.

We are not SOC 2 certified. That audit costs five figures and takes months. We would rather say we do not have it than imply we do. If procurement needs it, we are not your fit yet.

We do not have a dedicated security team. Four founders and a small group of assistants. Security is run by the founders, personally, against the checklist on this page.

If any of that rules us out, we would rather you knew now than three months in.

If you work in health

Read this before you hire a Health VA

Patient data carries obligations ordinary business data does not, and our setup has a real limitation: your assistant works on a personal machine we do not own.

Before placing anyone on health work we ask what data they will touch, whether it falls under HIPAA or the Philippine Data Privacy Act, and what your compliance team requires. If it needs managed, company-owned equipment, we will say we cannot do it yet rather than take the booking.

We would rather lose the sale than put you in breach.

Reporting something

If you find a problem

Email security@avassistph.com. A founder reads it, not a ticketing queue.

We acknowledge within one working day and tell you what we are doing. If it is serious, we will say so plainly rather than manage the language.

Have a need? aVAssist.

Ask us anything on this page before you commit.

Find aVAssist