Security

Security posture

Maintained by the Aivessa team.

Aivessa is in private beta. This page describes app-visible controls and the practices the Aivessa team commits to during the beta. Aivessa is not an independent certification authority.

Access and authentication

  • Email and password sign-in, plus optional Google sign-in.
  • Platform and organization roles enforced through database policies and server-side checks.
  • Only Aivessa reviewers can approve verifications or change credential status.

Platform and hosting context

Aivessa runs on managed cloud infrastructure with encryption in transit. Long-term production hardening is part of the private-beta roadmap.

Data collection

  • Account information: email, display name, avatar.
  • Organization and agent data you register.
  • Evidence you submit for verification.
  • Design-partner application responses and readiness assessment answers you submit.

Data you should not send us

Do not submit personal health information, payment card data, government identifiers, or third-party customer data through the private beta.

Contact

Report a security concern to security@aivessa.ai. See also our responsible disclosure page.

This page describes practices, not certifications. Aivessa does not currently claim SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent compliance.