← Back to Avertaq

Security

Security controls for a controlled pilot.

The essential boundary is simple: access is controlled, review data stays organization-scoped, and final decisions remain human. Open a control below only when you want the detail.

✓

Invitation-only access

Self-service signups are disabled. Pilot accounts are created deliberately for approved users.

✓

Organization-scoped authorization

Sensitive review and write operations are checked against authenticated organization membership and role.

✓

Private application routes

The secure workspace and API routes are not intended for search indexing and use private/no-store caching controls.

✓

Upload validation

Tender and supporting PDF workflows include file/signature validation, parser resource limits and controlled temporary-document handling. Uploads remain invitation-only until fail-closed malware scanning is implemented and verified.

✓

Browser security headers

Production uses CSP, HSTS, COOP, clickjacking protection, MIME-sniffing protection and restrictive permissions policies.

✓

Human review boundary

Avertaq supports review decisions; it does not silently convert AI output into final legal or compliance decisions.

Pilot-stage limitations

Avertaq does not currently claim malware-scanned public uploads, third-party security certifications, SSO, formal SLA coverage or enterprise-grade compliance attestations. Those capabilities will only be published if and when they are actually implemented and verified.

Report a security concern

Contact contact@avertaq.com. Do not attach tender or company evidence documents to email.