Security
Security posture
Maintained by the Aivessa team.
Aivessa is in private beta. This page describes app-visible controls and the practices the Aivessa team commits to during the beta. Aivessa is not an independent certification authority.
Access and authentication
- Email and password sign-in, plus optional Google sign-in.
- Platform and organization roles enforced through database policies and server-side checks.
- Only Aivessa reviewers can approve verifications or change credential status.
Platform and hosting context
Aivessa runs on managed cloud infrastructure with encryption in transit. Long-term production hardening is part of the private-beta roadmap.
Data collection
- Account information: email, display name, avatar.
- Organization and agent data you register.
- Evidence you submit for verification.
- Design-partner application responses and readiness assessment answers you submit.
Data you should not send us
Do not submit personal health information, payment card data, government identifiers, or third-party customer data through the private beta.
Contact
Report a security concern to security@aivessa.ai. See also our responsible disclosure page.
This page describes practices, not certifications. Aivessa does not currently claim SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent compliance.