Security
Security controls for a controlled pilot.
The essential boundary is simple: access is controlled, review data stays organization-scoped, and final decisions remain human. Open a control below only when you want the detail.
✓Invitation-only access
Self-service signups are disabled. Pilot accounts are created deliberately for approved users.
✓Organization-scoped authorization
Sensitive review and write operations are checked against authenticated organization membership and role.
✓Private application routes
The secure workspace and API routes are not intended for search indexing and use private/no-store caching controls.
✓Upload validation
Tender and supporting PDF workflows include file/signature validation, parser resource limits and controlled temporary-document handling. Uploads remain invitation-only until fail-closed malware scanning is implemented and verified.
✓Browser security headers
Production uses CSP, HSTS, COOP, clickjacking protection, MIME-sniffing protection and restrictive permissions policies.
✓Human review boundary
Avertaq supports review decisions; it does not silently convert AI output into final legal or compliance decisions.
Pilot-stage limitations
Avertaq does not currently claim malware-scanned public uploads, third-party security certifications, SSO, formal SLA coverage or enterprise-grade compliance attestations. Those capabilities will only be published if and when they are actually implemented and verified.
Report a security concern
Contact contact@avertaq.com. Do not attach tender or company evidence documents to email.