Security policy

Effective Date: 1 June 2026
Version: 1.0
Last Revised: 1 June 2026

Alvamy’s is committed to protecting your personal information and securing the systems, infrastructure, and all data entrusted to us. We consider the confidentiality of your information fundamental to the relationship between Alvamy’s and every collector, consignor, and visitor who interacts with our services.

This Security Policy explains the technical and organisational measures we use to protect your data, what you need to know about using our platform safely, and how to report a suspected security incident.

1. Our Security Commitment

Alvamy’s uses industry-leading security measures at every level of our platform, from the infrastructure hosting our systems to the way your password is stored.

Security is not an afterthought. It is integrated into our engineering, operations, and organisational culture.

Our security programme is aligned with internationally recognised frameworks, including:

  • ISO/IEC 27001 for Information Security Management.
  • The NIST Cybersecurity Framework.
  • PCI DSS for payment data.

We have a dedicated information-security team that continuously monitors threats, tests our defences, and responds to incidents.

CORE SECURITY COMMITMENTS
  • We encrypt all data in transit and sensitive data at rest.
  • We will never ask you for your password by email, telephone, or text message.
  • We will never send modified bank details by email or text message.
  • We conduct regular independent penetration tests.
  • We notify affected users within 72 hours of any confirmed personal-data breach.
  • We will never sell your personal data to third parties.
2a. Encrypted Connections
HTTPS / TLS

All pages of the Alvamy’s website and application use HTTPS, or Hypertext Transfer Protocol Secure, with TLS 1.2 encryption or higher.

This means that all data exchanged between your browser and our servers, including login credentials, personal information, and payment details, is encrypted in transit and protected against interception.

Our website uses HTTP Strict Transport Security, or HSTS, which instructs browsers to connect to our website only through HTTPS and helps prevent downgrade attacks.

Our TLS configuration is regularly assessed against current best practices and achieves an A or A+ rating in independent assessments.

2b. Password Protection
  • Your account is password-protected.
  • We strongly recommend using a unique and complex password of at least 12 characters that is not used on any other website.
  • Passwords are stored using one-way cryptographic hashing with a strong algorithm, such as bcrypt.
  • Your password is never stored in readable form.
  • Even authorised Alvamy’s personnel cannot retrieve your password.
  • If you forget your password, our system will send a time-limited password-reset link to your registered email address.
  • We will never send you your existing password.
  • We encourage the use of a password manager to generate and store strong, unique passwords.
2c. Two-Factor Authentication
2FA

We offer two-factor authentication for all registered accounts and strongly encourage you to enable it.

With 2FA enabled, signing in requires both:

  • Your password.
  • A unique code generated by an authentication application, such as Google Authenticator or Authy, or sent to your registered mobile number.

This means that even if your password is compromised, an attacker cannot access your account without the second factor.

Two-factor authentication is mandatory for accounts authorised to participate in high-value auctions or place high-value bids.

2d. Account Lockout and Brute-Force Protection

Our systems automatically detect and block repeated failed login attempts.

After a defined number of failed attempts, your account will be temporarily locked and you will receive an email notification.

If you did not attempt to sign in, contact our Security Team immediately at security@alvamys.com.

2e. Session Security
  • Login sessions are protected through secure, HTTP-only, and same-site cookies designed to resist cross-site scripting, or XSS, and cross-site request forgery, or CSRF, attacks.
  • Sessions automatically expire after a period of inactivity.
  • We recommend always signing out of your account when using a shared or public device.
  • Concurrent sessions across multiple devices are recorded.
  • You may review and terminate active sessions through your account security settings.
3. Data Security
3a. Encryption at Rest

Sensitive personal data stored in our databases, including identity documents, financial information, and contact details, is encrypted at rest using AES-256 encryption.

Database backups are also encrypted and stored in secure, geographically separate locations.

3b. Infrastructure Security
  • Our platform is hosted on enterprise-grade cloud infrastructure, including AWS, with SOC 2 Type II and ISO 27001 certifications.
  • Network traffic is filtered through multilayer firewalls and a Web Application Firewall, or WAF.
  • The WAF blocks known attack patterns, including SQL injection, cross-site scripting, and credential-stuffing attacks.
  • Intrusion detection and prevention systems, or IDS/IPS, continuously monitor network traffic for abnormal behaviour.
  • Our infrastructure is segregated into security zones.
  • Customer-facing systems are isolated from internal administrative systems.
  • Access to production systems is limited to authorised personnel using multifactor authentication and encrypted VPN connections.
  • All administrative access is logged and audited.
3c. Payment Security
PCI DSS

Alvamy’s complies with the Payment Card Industry Data Security Standard, or PCI DSS.

All card-payment processing is handled by our certified payment processor, Stripe, Inc., using its PCI DSS Level 1-certified infrastructure.

Alvamy’s does not store, process, or transmit complete card numbers within its own systems.

When you enter payment details on our platform:

  • Your card information is tokenised at the point of entry.
  • The information is transmitted directly and securely to our payment processor.
  • Alvamy’s retains only a payment token and the last four digits of your card number for reference purposes.
3d. Data Minimisation and Retention

We collect only the personal data required for the purposes described in our Privacy Policy.

Data is retained only for as long as necessary and is securely deleted or anonymised after the applicable retention period expires.

Access to personal data within Alvamy’s is restricted on a need-to-know basis through role-based access controls.

4. Fraud Awareness

Cybercrime is increasing globally, and the art market is not immune.

We want to ensure that every Alvamy’s customer understands the most common threats and knows exactly how to remain safe.

Please read this section carefully.

4a. Bank-Account and Payment Fraud
CRITICAL WARNING

Alvamy’s will NEVER change its bank-transfer details by email or text message.

If you receive any communication, through any channel, claiming to be from Alvamy’s and informing you of new, modified, or “updated” bank details, treat it as fraudulent.

DO NOT transfer funds until you have called us directly using a telephone number published on our official website.

Alvamy’s will not be responsible for losses resulting from payments made to fraudulent bank accounts.

A common fraud technique known as Business Email Compromise, or BEC, also referred to as payment-diversion fraud, involves intercepting or impersonating emails from art dealers and auction houses to redirect bank transfers to fraudulent accounts.

Our payment-instruction procedures are as follows:

  • Our bank details will be provided only in writing by your Alvamy’s relationship manager or through your secure account dashboard.
  • If you receive any email or message that appears to update or change our payment details, call us immediately before making any transfer.
  • Always verify bank-account details by calling your Alvamy’s contact using a telephone number obtained independently from our official website.
  • Do not use a telephone number included in a suspicious email.
4b. Impersonation and Social Engineering

We are aware of an increasing number of fraudsters falsely impersonating Alvamy’s employees, specialists, and agents to request payment for fictitious services.

Common fraudulent requests include:

  • Fees for valuations or expert assessments that were not previously agreed in writing.
  • “Security deposits” or “release fees” required to obtain alleged sale proceeds.
  • Requests for gift-card payments or cryptocurrency transfers as advance fees.
  • Unsolicited offers to sell objects on your behalf that require advance registration fees or commissions.

Alvamy’s will never request:

  • Advance-fee payments.
  • Security deposits.
  • Gift-card payments as a condition for releasing sale proceeds.
  • Gift-card payments as a condition for providing any service.

Where you are uncertain, contact us directly.

4c. Phishing and Fake Websites

Phishing attacks use emails, text messages, or fake websites that appear to come from legitimate businesses in order to steal login credentials or personal information.

  • Always verify that the address displayed in your browser is exactly https://www.alvamys.com before entering personal or payment information.
  • Look for the padlock icon in your browser’s address bar, confirming that the connection is encrypted.
  • Be suspicious of emails urging you to click a link to “verify your account” or “confirm payment details.”
  • Alvamy’s will never ask for your password or complete payment details by email.
  • Do not open attachments from unexpected emails claiming to be from Alvamy’s without first confirming their legitimacy by telephone.
4d. Telephone and Auction Fraud

If you receive an unsolicited telephone call from someone claiming to represent Alvamy’s and requesting payment or personal information, do not provide any information.

End the call and telephone us using one of our published contact numbers.

Genuine Alvamy’s personnel will never object to this precaution and will always encourage you to verify the call.

4e. What to Do if You Suspect Fraud

If you receive any communication that you believe may be fraudulent, or if you suspect that your account has been compromised:

  • Do not click any links.
  • Do not transfer any funds.
  • Contact us immediately at security@alvamys.com.
  • Alternatively, call your relationship manager using one of our published telephone numbers.
  • Keep the suspicious email or message and do not delete it, as it may be required for investigation.
  • Report the incident to your local cybercrime authority, such as FBI IC3 in the United States, Action Fraud in the United Kingdom, or DIICOT in Romania.
  • If funds have already been transferred, contact your bank immediately and request an attempt to recall the transaction.
5. Employee and Internal Security

Alvamy’s treats internal security with the same seriousness as external threats.

Our internal security programme includes the following measures.

5a. Access Controls
  • Access to customers’ personal data is limited to personnel who need the information to perform their duties, based on the principle of least privilege.
  • All staff access to systems containing personal data is protected by multifactor authentication.
  • Access privileges are reviewed quarterly.
  • Access is revoked immediately when a staff member leaves the organisation.
  • Administrative access to databases and infrastructure requires dual authorisation for sensitive operations.
5b. Security Training
  • All Alvamy’s personnel complete mandatory information-security and data-protection training when they join the organisation and annually thereafter.
  • Personnel are trained to recognise phishing emails, social-engineering attempts, and suspicious activity.
  • Specialist staff managing high-value transactions receive additional training concerning financial fraud and impersonation risks.
5c. Background Checks

All employees and contractors who have access to customer data undergo appropriate background checks consistent with:

  • The sensitivity of the data they will handle.
  • The laws applicable in their jurisdiction.
5d. Confidentiality

All personnel handling customer data are bound by confidentiality obligations as a condition of their employment or contract.

Unauthorised disclosure of customer data constitutes disciplinary misconduct and may result in legal action.

6. Vulnerability Management and Testing
  • Alvamy’s regularly conducts independent penetration testing of its web applications, APIs, and network infrastructure.
  • Testing is conducted at least annually and following any significant platform changes.
  • We operate a continuous vulnerability-scanning programme covering infrastructure, application code, and third-party dependencies.
  • Critical security patches are deployed within 24 hours of release.
  • High-severity patches are deployed within seven days.
  • All other patches are applied within 30 days.
  • We conduct static and dynamic application-security testing, or SAST and DAST, as part of our software-development lifecycle.
  • No code is deployed to production without a security review.
  • We regularly conduct tabletop exercises and incident-response simulations to test our readiness to respond to security incidents.
7. Responsible Disclosure
Reporting a Vulnerability

Alvamy’s values reports from security researchers and members of the public who discover potential vulnerabilities in our systems.

If you believe you have identified a security issue, please report it responsibly before disclosing it publicly.

7a. How to Report

Email: security@alvamys.com

A PGP key is available upon request for encrypted submissions.

Please include the following information in your report:

  • A clear description of the vulnerability.
  • Steps required to reproduce it, including the URL, payload, screenshots, or video where applicable.
  • The potential impact according to your assessment.
  • Your contact details, which are optional but helpful for follow-up.
7b. Our Commitments to Researchers
  • We will acknowledge receipt of your report within three working days.
  • We will investigate and aim to confirm or disprove the vulnerability within 10 working days.
  • We will keep you informed about remediation progress.
  • We ask you not to disclose the vulnerability publicly until we have had a reasonable opportunity to correct it, generally 90 days.
  • We will not initiate legal proceedings against researchers who act in good faith, do not access or modify customer data, and comply with responsible-disclosure practices.
7c. Scope

In scope:

  • www.alvamys.com.
  • Our mobile applications.
  • Any subdomains or services clearly operated by Alvamy’s.

Out of scope:

  • Denial-of-service attacks.
  • Physical-security testing.
  • Social engineering directed at Alvamy’s personnel.
  • Automated scanning without prior permission.
  • Testing of systems belonging to our third-party service providers.
8. Security-Incident Response

Alvamy’s maintains a formal incident-response plan that is reviewed and tested annually.

Where a security incident is confirmed, the following process applies.

StageActions and Timeframe
Detection and triageAutomated monitoring and manual review identify the incident. The Security Team is notified immediately.
ContainmentAffected systems are isolated within hours of detection to limit exposure.
InvestigationA root-cause analysis is conducted. The scope and impact of the data exposure are assessed.
NotificationAffected users are notified within 72 hours of the confirmed breach where required by the GDPR. Regulatory authorities are notified as required by law.
RemediationThe vulnerability is corrected, systems are hardened, and access credentials are reset where appropriate.
Post-incident reviewA complete review is concluded within 30 days. Lessons learned are incorporated into our security programme.

We will communicate honestly and promptly with affected customers.

We will provide clear information concerning:

  • What happened.
  • What data was involved.
  • What action we have taken.
  • What steps we recommend that you follow to protect yourself.
9. Third-Party and Supplier Security

Alvamy’s works only with third-party service providers that meet our security standards.

Before integrating any provider with access to customer data, we conduct a security assessment.

All such providers must:

  • Maintain appropriate technical and organisational security measures.
  • Process data only in accordance with our documented instructions.
  • Notify us without undue delay of any security incident affecting our data.
  • Submit to audits and assessments that we reasonably require.
  • Delete or return all customer data when the relationship ends.

Our principal technology partners, including AWS, Stripe, and SendGrid, are industry leaders in security and maintain relevant certifications, including SOC 2, ISO 27001, and PCI DSS, appropriate to the services they provide.

10. Your Responsibilities

Security is a shared responsibility.

Although Alvamy’s invests significantly in securing our systems, you can substantially reduce your risk by following these good practices.

ActionWhy It Matters
Use a strong and unique passwordPrevents access if another website you use is compromised.
Enable two-factor authenticationPrevents account takeover even if your password is stolen.
Keep your email account securePassword-reset messages are sent to your email, making it a key part of your account security.
Sign out on shared devicesPrevents other people from accessing your session.
Verify payment instructions by telephoneProtects against bank-transfer fraud.
Keep your device operating system and browser updatedInstalls fixes for known vulnerabilities that attackers may exploit.
Be cautious with links in emailsPhishing is one of the most common methods used to compromise accounts.
Report suspicious activity promptlyEarly reporting helps limit potential damage.
11. Contact Us

If you have security concerns, suspect fraud, or wish to report a vulnerability, please use the dedicated contact channels below.

Our Security Team continuously monitors these channels.

Security and Fraud Enquiries

Security email: security@alvamys.com
Fraud email: fraud@alvamys.com

Telephone

Available Monday to Friday, from 09:00 to 18:00 local time:

Republic of Moldova: +373 794 81 777
Bucharest: +373 794 81 777

For urgent matters outside normal working hours, please call our New York number and follow the instructions for the emergency security line.

Postal Address

Alvamy’s Information Security Team
42 Mihai Viteazul Street
Bălți Municipality
Republic of Moldova

We aim to acknowledge all security enquiries within one working day.

For suspected active fraud or account compromise, please telephone us directly and do not rely solely on email.