Support Centre

Frequently Asked Questions

Everything you need to know about Averox and our products. Can't find an answer? Our team is happy to help.

All Questions48
ASVP Platform12
Pricing & Plans8
Security & Compliance8
Deployment7
Partners6
Other Solutions7
Browse by Category
All Questions 48
ASVP Platform 12
Pricing & Plans 8
Security & Compliance 8
Deployment 7
Partner Program 6
Other Solutions 7
Still have questions?
Our security experts are available to answer any question you have.
Contact Support
ASVP Platform
12 questions
What is ASVP and how does it differ from a traditional penetration test?
ASVP (Autonomous Security Validation Platform) is Averox's continuous, automated security validation platform that simulates real-world attacks against your live defenses 24/7. Unlike a traditional penetration test — which is a point-in-time assessment conducted manually, typically once or twice a year — ASVP runs thousands of attack simulations mapped to the MITRE ATT&CK framework every day. A pentest gives you a snapshot; ASVP gives you a living, always-current view of your true security posture. ASVP also costs significantly less than ongoing manual pentesting while providing far greater coverage and continuity.
ASVPBASPentest vs ASVP
How quickly can ASVP be deployed in our environment?
ASVP uses agentless deployment and integrates with your existing SIEM, EDR, firewall, and cloud environments in under 30 minutes. There is no software to install, no agents to deploy, and no complex infrastructure changes required. Most clients run their first security simulation within the first hour of connecting the platform. Our implementation team provides guided onboarding and is available throughout the process.
DeploymentAgentlessSetup
Will ASVP simulations disrupt our production environment?
No. ASVP is designed to be completely safe for production environments. All attack simulations are conducted using controlled, non-destructive techniques that mimic real attacker behavior without causing actual damage, data loss, or service disruption. ASVP has been running in live enterprise environments — including banks, hospitals, and government agencies — without a single production incident. You can also configure simulation windows, exclusion lists, and intensity levels to match your operational requirements.
SafetyProductionNon-Destructive
Which security tools does ASVP integrate with?
ASVP integrates natively with 50+ security tools across all major categories: SIEM (Splunk, Microsoft Sentinel, IBM QRadar), EDR (CrowdStrike, SentinelOne, Microsoft Defender), firewalls (Palo Alto, Fortinet, Check Point), cloud security (AWS Security Hub, Azure Defender, Google Chronicle), and ticketing (ServiceNow, Jira). ASVP measures whether your actual deployed tools detect and block the simulations — making these integrations the core of how it delivers value. Custom integrations are available via REST API for enterprise deployments.
IntegrationsSIEMEDR
What is the MITRE ATT&CK framework and how does ASVP use it?
MITRE ATT&CK is a globally recognized knowledge base of real-world adversary tactics and techniques, maintained by the non-profit MITRE Corporation. It documents exactly how attackers operate — from initial access through execution, persistence, privilege escalation, lateral movement, and data exfiltration. ASVP maps all 5,000+ of its attack scenarios directly to MITRE ATT&CK techniques and threat actor profiles, so every simulation represents how a real adversary would attack your specific environment. This means your security score reflects your actual defensive coverage against real threats — not theoretical vulnerabilities.
MITRE ATT&CKTTPsThreat Actors
Do you offer a proof of concept (POC) before purchase?
Yes. We offer a structured 14-day proof of concept for enterprise clients, fully guided by our security engineering team. The POC is conducted in your live environment against your actual security controls. At the end of the POC period, you receive a complete security validation report showing exactly what ASVP found — the gaps, the control effectiveness scores, and prioritized remediation recommendations. This gives you concrete evidence of value before any purchase decision.
POCFree Trial14-Day
How is the ASVP security score calculated?
The ASVP security score is a dynamic, weighted metric that reflects the percentage of simulated attacks that your security controls successfully blocked or detected. It factors in attack severity, technique coverage across the MITRE ATT&CK matrix, the criticality of affected assets, and whether your tools generated the appropriate alerts. The score is updated continuously after every simulation run — unlike CVSS scores, which are static theoretical ratings. A higher score means your defenses actually stop attacks; a lower score tells you exactly where the gaps are and what to prioritize.
Security ScoreMetricsScoring
Can ASVP replace our annual penetration test for compliance purposes?
In many cases, yes — and often it provides stronger evidence of compliance than a traditional pentest. ASVP generates machine-readable, continuous evidence of security control effectiveness that is accepted by auditors for ISO 27001, SOC 2, PCI-DSS, NCA ECC, SAMA, and NIST frameworks. However, some regulatory requirements still mandate a human-conducted penetration test at specific intervals. Our compliance team can advise on exactly what ASVP covers for your specific regulatory obligations and where supplementary testing may still be required.
CompliancePentestAudit
What ASVP features are available for the specific modules (Continuous Validation, ASM, API Security etc.)?
ASVP is a modular platform with 8 core capability areas: Continuous Security Validation, Attack Surface Monitoring, API Security Testing, DevSecOps Pipeline Security, WAF Detection & Validation, Compliance Readiness, Repository Risk Scoring, and Threat Exposure Analysis. Each module can be licensed individually or as part of the full suite. Enterprise licenses include all modules. You can explore detailed information about each module on the ASVP Features page.
ModulesFeaturesLicensing
How does ASVP handle false positives?
Because ASVP controls both the attack simulation and the measurement of detection, false positives are extremely rare — typically less than 0.1% of findings. Unlike vulnerability scanners that guess at risk, ASVP executes actual techniques and measures actual control responses. If a control blocks or detects the simulation, that's a true positive result. If it doesn't, that's a true gap. Our AI also reviews findings before surfacing them to reduce noise further. Customers can also mark specific findings for review or suppression through the dashboard.
False PositivesAccuracyAI
Does ASVP support cloud environments (AWS, Azure, GCP)?
Yes. ASVP provides full coverage across AWS, Azure, and Google Cloud Platform — including cloud-specific attack scenarios like S3 bucket misconfiguration exploitation, IAM privilege escalation, container escape, serverless function abuse, and cloud metadata service attacks. ASVP integrates with AWS Security Hub, Azure Defender for Cloud, and Google Chronicle to measure cloud security control effectiveness. Attack Surface Monitoring also continuously scans your cloud footprint for unknown and misconfigured assets.
AWSAzureGCPCloud
What kind of reports does ASVP generate?
ASVP generates multiple report types tailored to different audiences: Executive Security Posture Reports (board-ready, business-risk language), Technical Remediation Reports (specific fix guidance for security engineers), Compliance Evidence Reports (control coverage mapped to specific frameworks like ISO 27001, NCA ECC, PCI-DSS), MITRE ATT&CK Coverage Maps (heatmap of your detection coverage across all 14 tactics), and Trend Reports (posture improvement or degradation over time). All reports are available on-demand at any time from the dashboard, or scheduled for automatic delivery.
ReportsExecutiveCompliance
Pricing & Plans
8 questions
How is ASVP priced?
ASVP is priced based on your environment size — specifically the number of assets (IPs, domains, cloud resources) you want to cover, and the modules you require. Pricing is annual subscription-based with no per-simulation or per-finding fees. We offer three main tiers: Essentials (for mid-market organizations), Enterprise (full modules, unlimited assets within scope), and Custom (for large enterprises and government with specific requirements). Contact our sales team for a tailored quote — most organizations receive pricing within 24 hours of a brief scoping call.
PricingLicensingSubscription
Is there a free trial available?
Yes. We offer a 14-day guided proof of concept in your live environment — no credit card required. The POC includes full access to ASVP platform capabilities, onboarding from our security engineering team, and a complete security validation report at the end. This gives you a real, evidence-based view of what ASVP would find in your environment before making any commitment. Request a POC here.
Free TrialPOC
Do you offer discounts for multi-year contracts?
Yes. We offer meaningful discounts for 2-year and 3-year commitments. Multi-year agreements also include locked pricing for the contract term — protecting you from any future price increases. Our enterprise sales team can discuss flexible payment options including quarterly billing for annual contracts. Contact sales@averox.com for details.
DiscountsMulti-Year
Is there special pricing for government or non-profit organizations?
Yes. We offer special pricing programs for government agencies, non-profit organizations, and educational institutions. Government pricing includes additional compliance support for national regulatory frameworks (NCA ECC, SAMA, CBUAE). Please contact our public sector team at gov@averox.com with details about your organization.
GovernmentNon-ProfitEducation
What's included in the Enterprise plan?
The Enterprise plan includes all 8 ASVP modules (Continuous Validation, ASM, API Security, DevSecOps, WAF Validation, Compliance Readiness, Repository Risk Scoring, Threat Exposure Analysis), unlimited simulations, a dedicated Customer Success Manager, priority technical support with 4-hour SLA, custom integrations, on-premise or private cloud deployment options, custom compliance framework mapping, and executive reporting packages. For very large deployments, we also offer dedicated infrastructure and custom SLAs up to 99.99% uptime.
EnterprisePlan Features
Can I add or remove modules after signing up?
Yes. ASVP is designed to be modular and flexible. You can add new modules at any time during your subscription at a pro-rated price. Removing modules is possible at renewal. We recommend starting with the modules most relevant to your current priorities and expanding as your security program matures. Your Customer Success Manager can help you plan the right rollout sequence.
ModulesFlexible
Do you offer MSSP / reseller pricing?
Yes. We have a dedicated Reseller Program for VARs, MSSPs, and distributors who want to include ASVP in their security service portfolio. Partners receive competitive discount tiers (up to 35%), deal registration protection, pre-sales support, and recurring commission on renewals. Visit our Partner Program page or email info@averox.com to apply.
MSSPResellerPartners
What payment methods do you accept?
We accept all major credit and debit cards (Visa, Mastercard, Amex), bank wire transfer, and purchase orders for enterprise customers. We can issue invoices in USD, GBP, AED, SAR, and PKR. For government and large enterprise clients, we support procurement through approved vendor channels and can work with your finance team on payment terms. Contact billing@averox.com for billing questions.
PaymentBillingInvoice
Security & Compliance
8 questions
How does Averox protect our data?
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. ASVP operates on a zero-knowledge principle for your sensitive assets — simulation data is processed in memory and never stored on our systems beyond what is necessary for reporting. We maintain SOC 2 Type II certification, undergo annual third-party penetration tests, and provide a Data Processing Agreement (DPA) for all enterprise customers. Customer data is never used to train models, shared with third parties, or used for any purpose outside your specific deployment.
Data ProtectionEncryptionSOC 2
Which compliance frameworks does ASVP support?
ASVP maps security validation results to 15+ regulatory frameworks including: ISO 27001, NCA ECC (Saudi Arabia), SAMA Cybersecurity Framework, CBUAE (UAE), NIST CSF, NIST SP 800-53, PCI-DSS, HIPAA, SOC 2, GDPR, IEC 62443 (OT/ICS), NERC CIP (Energy), and regional frameworks across GCC countries. For each framework, ASVP generates audit-ready evidence showing which controls are validated, which have gaps, and the remediation actions taken — accepted by auditors as operational evidence of control effectiveness.
ISO 27001NCA ECCPCI-DSSNIST
Is ASVP GDPR compliant?
Yes. Averox is fully GDPR compliant. We maintain a Data Processing Agreement available for all customers, process personal data only as necessary for service delivery, and can provide EU data residency options for European customers. Our privacy-by-design architecture ensures no sensitive personal data is retained beyond defined retention periods. Averox Europe Ltd, our UK/EU entity at 3rd Floor 86-90 Paul Street, London EC2A 4NE, serves as the data controller for European customers. Email privacy@averox.com for GDPR inquiries.
GDPRPrivacyData Residency
Where is our data stored? Can we choose our data region?
ASVP is hosted on AWS with primary regions in UAE (me-south-1) and UK (eu-west-2). Customers can select their preferred data residency region during onboarding. Enterprise and government customers can also opt for on-premise deployment where all data stays entirely within your own infrastructure. We can also accommodate custom data residency requirements for organizations with specific regulatory constraints — contact our team to discuss your requirements.
Data ResidencyUAEOn-Premise
Does Averox conduct its own security testing?
Yes. We practice what we preach — ASVP validates our own infrastructure continuously, and we commission annual third-party penetration tests of our platform conducted by independent security firms. We also run a responsible disclosure program for security researchers. If you discover a security vulnerability in any Averox product or service, please report it to security@averox.com. We acknowledge all reports within 24 hours.
PentestBug BountyDisclosure
What access does Averox staff have to our environment?
No Averox staff has access to your production environment or your data. ASVP operates through API connections and read-only integrations — our platform never requires privileged access to your systems. For support purposes, if you grant our team time-limited, audited access to your ASVP dashboard (not your environment), this is logged and visible to you at all times. All Averox staff with any access to infrastructure are background-checked and operate under strict access control policies.
Access ControlPrivacy
Does ASVP support role-based access control (RBAC)?
Yes. ASVP includes granular role-based access control with pre-built roles (Admin, Security Engineer, Analyst, Executive Viewer) and custom role creation. Permissions can be scoped to specific asset groups, business units, or geographic regions — ideal for large enterprises where different teams should only see data relevant to their scope. SSO integration (SAML 2.0, OIDC) is included in Enterprise plans, enabling your existing identity provider to manage ASVP access.
RBACSSOAccess Control
What is Averox's uptime SLA?
Averox guarantees 99.9% uptime for all commercial plans (equivalent to less than 8.7 hours downtime per year). Enterprise plans with dedicated infrastructure offer 99.99% SLA. In the event of an SLA breach, customers receive service credits as specified in the enterprise agreement. You can monitor current platform status and historical uptime at status.averox.com.
SLAUptimeAvailability
Deployment & Technical
7 questions
What are the technical requirements to deploy ASVP?
ASVP requires no on-premise hardware or software installation. All you need is: (1) Network connectivity — ASVP connects to your environment via API or an optional lightweight connector deployed in a DMZ; (2) Integration credentials — read-only API keys for your SIEM, EDR, and firewall; (3) A modern web browser to access the dashboard. Minimum recommended integration is your SIEM and one EDR. Our onboarding team walks you through the entire setup in a single 90-minute session.
RequirementsTechnicalSetup
Can ASVP be deployed on-premise?
Yes. Enterprise customers can deploy ASVP entirely on their own infrastructure — on-premise in your data center, or in your private cloud (AWS GovCloud, Azure Government, etc.). On-premise deployments offer complete data sovereignty and are ideal for government, defense, and highly regulated financial institutions. ASVP is packaged as containers (Docker/Kubernetes) for easy on-premise deployment. Our implementation team handles the full on-premise deployment and configuration.
On-PremisePrivate CloudData Sovereignty
Does ASVP work in air-gapped environments?
Yes, with our on-premise deployment option. Fully air-gapped deployments are supported for classified and sensitive environments. In air-gapped mode, threat intelligence updates are delivered via a secure, offline update mechanism (encrypted package delivered on approved media). This is available to government and defense customers under our Enterprise program. Contact our public sector team to discuss air-gapped deployment architecture.
Air-GappedGovernmentClassified
How long does onboarding take?
For SaaS deployments, most customers complete onboarding in 1–2 days: initial integration setup in under 30 minutes, first simulation run within the first hour, and full platform configuration within the first two days. On-premise deployments typically take 3–5 business days. All plans include a dedicated onboarding session with our security engineering team. Enterprise plans include a structured 30-day onboarding program with weekly check-ins to ensure maximum value from day one.
OnboardingSetup Time
What support is available after deployment?
All plans include email and chat support during business hours (Mon–Fri, 9AM–6PM GMT) with a 24-hour response SLA. Enterprise plans include dedicated Customer Success Manager, priority support with 4-hour response SLA, quarterly security review calls with our engineering team, and access to our 24/7 emergency incident support line for critical issues. We also provide a comprehensive online knowledge base, video training library, and API documentation.
SupportSLACustomer Success
Does ASVP have a REST API?
Yes. ASVP provides a comprehensive REST API that allows you to programmatically trigger simulations, retrieve findings, pull security scores, manage assets, and integrate ASVP data into your own dashboards, SOAR platforms, or reporting workflows. Full API documentation is available at docs.asvp.averox.com. API access is included in all plans, with rate limits scaled by plan tier. Webhooks are also available for real-time event notifications.
APIRESTIntegration
What regions does Averox operate in?
Averox has offices and active operations across the United Kingdom (HQ: London EC2A 4NE), United States (Wilmington, DE), and active partners across the GCC (UAE, Saudi Arabia, Qatar, Kuwait, Bahrain), South Asia (Pakistan, India), and wider MENA region. ASVP is used by customers in 12+ countries and our cloud infrastructure supports data residency in UAE (AWS me-south-1) and UK (AWS eu-west-2). We support customers globally via our partner network.
RegionsGlobalGCC
Partner Program
6 questions
What partner programs does Averox offer?
Averox offers three partner programs: Technology Partner (for ISVs and product vendors who want to integrate with ASVP), Reseller Program (for VARs, distributors, and security resellers who want to sell ASVP to their customers), and System Integrator Program (for consulting firms, MSSPs, and SIs who deploy and manage ASVP for enterprise clients). Each program has its own track, benefits, and margin structure. Visit our Partner Program page for full details.
Technology PartnerResellerSI
How do I apply to become an Averox partner?
You can apply through our Partner Program page or email info@averox.com directly. Our partner team reviews all applications within 2 business days. After approval, partners are scheduled for a discovery call with a Partner Success Manager to align on the right program track, set revenue targets, and start onboarding. Most partners are selling within 2 weeks of approval.
ApplyOnboarding
What margins and commissions do resellers receive?
Reseller partners receive competitive margins on ASVP license sales (up to 35% depending on tier and deal size), 15% recurring commission on annual renewals they manage, and additional deal registration bonuses for new logo opportunities. Gold and Elite tier partners receive enhanced margins, MDF marketing funds, and access to co-sell opportunities with the Averox field team. Full margin structure is shared during the partner onboarding process.
MarginsCommissionRecurring
What training and certification does Averox provide to partners?
All partners receive access to the Averox Partner Portal, which includes a complete online training library (sales fundamentals, technical deep-dives, product demos), certification programs (Averox Certified Sales Professional and Averox Certified Technical Engineer), co-branded sales materials, and demo sandbox access. Certification training takes approximately 6–8 hours and is self-paced. In-person training workshops are also available for Gold and Elite partners.
TrainingCertificationPartner Portal
Can partners white-label ASVP?
White-label options are available for System Integrator and MSSP partners at the Elite tier. White-labeling allows partners to present ASVP under their own brand name and interface — ideal for MSSPs who want to deliver continuous security validation as a managed service under their brand. White-label agreements include custom dashboard branding, report templates, and client-facing portal customization. Contact our partner team to discuss white-label terms.
White-LabelMSSPElite Tier
Does Averox provide pre-sales support for partner-led deals?
Yes. All registered partners have access to Averox Sales Engineering support for pre-sales activities — including technical demos, proof of concept delivery, RFP and RFI response support, and security architecture consultations for client engagements. For Gold and Elite partners, a dedicated Averox Sales Engineer is assigned to their top deals. We want our partners to win, and we invest alongside you in every opportunity.
Pre-SalesSales EngineeringCo-Sell
Other Averox Solutions
7 questions
What other products does Averox offer beyond ASVP?
In addition to ASVP, Averox offers a suite of enterprise business solutions: ERP & CRM (business management platform), DocsMove (EDMS and advanced eSign solution), Bleupage (social media management and marketing platform), Averox Communication Platform (branded messaging app and enterprise video conferencing), Averox Productivity Tracker (employee productivity and activity tracking), Legal Case Management (for banks and corporate legal teams), and Averox PKI (enterprise public key infrastructure). Each is available as a standalone product or as part of an integrated Averox enterprise suite.
ERPDocsMovePKIBleupage
What is DocsMove and how does it differ from DocuSign?
DocsMove is Averox's enterprise Electronic Document Management System (EDMS) with advanced eSign capabilities built in. Unlike DocuSign — which is primarily a signing workflow tool — DocsMove is a complete document lifecycle platform covering storage, version control, access control, approval workflows, template management, retention policies, and eSign in a single solution. DocsMove also includes biometric verification, OTP-based identity confirmation, blockchain-anchored audit trails, and compliance with eIDAS, ESIGN, UAE TRA, and other regional frameworks.
DocsMoveeSignEDMS
Is the Averox Communication Platform truly end-to-end encrypted?
Yes. Every message, call, file, and video session on the Averox Communication Platform is end-to-end encrypted using AES-256 with forward secrecy — meaning even Averox cannot read your communications. The platform can be deployed on your own infrastructure (on-premise or private cloud), so your communications never pass through third-party servers. We also provide admin controls for message retention, data export, and remote device wipe for enterprise compliance requirements.
E2E EncryptionCommunicationPrivacy
How does the Averox Productivity Tracker handle employee privacy?
Averox Productivity Tracker is built with a privacy-first approach. Key privacy features: (1) Employees have full access to their own data — the same view their manager sees; (2) Tracking automatically pauses outside configured work hours and weekends; (3) A personal browsing mode allows employees to pause tracking for personal tasks with one click, no justification required; (4) Screenshots are optional, configurable, and visible to the employee; (5) All data is only retained for the period configured by your organization. We believe productivity monitoring only works when employees trust the system.
PrivacyProductivityEmployee Trust
Can the Legal Case Management system be used by both in-house legal teams and law firms?
Yes. Averox Legal Case Management is designed for both corporate legal departments (particularly in banking and financial services) and external law firms. For corporate legal teams, it provides matter management, regulatory correspondence tracking, contract lifecycle management, and NPL portfolio tracking. For law firms, it adds client billing, billable hour capture, matter-based time tracking, and client portal access. The system is particularly strong for organizations that need to manage high-volume regulatory matters and litigation portfolios simultaneously.
LegalBankingLaw Firms
What makes Bleupage different from Hootsuite or Buffer?
Bleupage is designed for marketing agencies and enterprise marketing teams who need more than a scheduling tool. Key differentiators include: AI content generation trained on your brand voice, built-in paid ad management (Facebook, Instagram, LinkedIn, TikTok) from the same dashboard, a client-facing content approval portal for agencies, social listening across 50+ platforms, competitive benchmarking, and team collaboration workflows with role-based access. Bleupage also offers white-label options for agencies who want to present it as their own platform to clients.
BleupageSocial MediaAgencies
Can I use multiple Averox products together as an integrated suite?
Yes. Averox products are designed to work both standalone and as an integrated enterprise suite. Key integrations include: ASVP connects with your entire security stack; DocsMove integrates with ERP/CRM for contract management and with Legal for matter documentation; Communication Platform integrates with ERP for team notifications; Productivity Tracker feeds data into HR modules of ERP. Organizations using multiple Averox products receive consolidated billing, a single Customer Success Manager, and priority cross-product support. Contact our sales team for bundle pricing.
SuiteIntegrationBundle
Still Need Help?

Can't Find What You're Looking For?

Our team is here to help. Reach out through any of the channels below and we'll get back to you within one business day.

Email Us
Send your question and our team will respond within one business day — guaranteed.
info@averox.com
Book a Demo
See ASVP in action with a 30-minute live demo tailored to your environment and security stack.
Schedule a Demo
Partner Inquiries
Interested in reselling, integrating, or becoming an Averox system integrator? Let's talk.
info@averox.com

Ready to See ASVP in Action?

Book a 30-minute live demo and see exactly what ASVP would find in your environment — no commitment required.

We develop, implement and support business critical software solutions.

Averox Europe Ltd.

Averox Inc.