Trust & Safety
Security & Privacy
Avori is built local-first. Your source code, design docs, chats, and project memory stay under your control, and your content is not used for training.
Our commitments
No training on your content
Your source code, design docs, prompts, and project context are not used for model training. Avori is built for commercial projects where unreleased mechanics, lore, and production plans need to stay yours.
TLS in transit
Account, billing, update, diagnostic, and model-request traffic is encrypted in transit. Local engine communication stays on your machine.
Sanitized error reports
Automatic reports are bounded to technical metadata and sanitized stack frames. They exclude prompts, projects, GDDs, keys, payment data, balances, and absolute paths, and are available only in the founder-authenticated support queue.
Authentication secured
Authentication uses signed JWTs. User sessions are validated server-side and scoped to the authenticated account to enforce account-specific access.
No data sold to third parties
We do not sell or rent your usage data, code context, or personal information to advertisers or data brokers. Service providers receive only the data needed to provide the selected feature.
Hub runs locally
Avori is a native background service that runs on your machine. Project context, GDDs, pages, rules, chats, and project memory are local-first and do not sync to a cloud workspace by default.
Account data isolation controls
Server-side authorization, row-level security, role checks, and fail-closed gates separate account, subscription, wallet, organization, and support data. Security reports remain subject to ongoing testing and independent review.
What goes where
A transparent breakdown of every data type Avori touches, where it goes, and who can access it.
Swipe sideways to compare where each data type goes and who can access it.
| Data Type | Where It Goes | Who Can See It |
|---|---|---|
| AI Prompts & Code Context | Sent as necessary request context to the model provider and funding route you selected | The selected provider processes the request; Avori does not use it for training |
| Project files, GDDs & context | Local by default. Pro sync or a Cloud Loop uses encrypted cloud storage or isolated cloud processing only after you enable it. | You and the Avori services needed to provide the cloud feature you enabled; never used for training |
| Billing and wallet data | Remote database (RLS-protected) | You only; Avori backend for software entitlement and wallet reservation/settlement |
| Email Address | Auth provider; Resend for transactional email | Avori account operations and the service providers needed for authentication and email delivery |
| Payment Information | Stripe (we never see raw card data) | Stripe only |
| Error reports | Private support storage after strict client and server allowlist checks | Founder-authenticated Avori support only; never includes prompts, project content, credentials, payment data, balances, or absolute paths |
| Website analytics | Limited public-page, referral, campaign, tutorial, navigation, and engagement events sent to Google Analytics | Avori and Google Analytics for aggregate website measurement; events exclude prompts, project content, provider keys, payment details, and wallet balances |
| Chat History | Local by default; encrypted multi-device continuity is available only when a Pro user enables cloud sync | You; Avori's cloud service handles encrypted synchronization only when enabled |
Responsible Disclosure
Found a security vulnerability? Please report it. We review reports as promptly as possible and will work with you to investigate and resolve confirmed issues responsibly.
security@avorihq.comWe don't run a formal bug bounty program, but we will acknowledge your contribution publicly if you'd like.
Compliance status
This page describes current product controls. It is not a certification or a substitute for your organization’s legal or security review.
SOC 2
Avori is not currently SOC 2 certified. Do not treat product architecture or internal testing as certification.
Privacy requests
Account data export and deletion requests are handled through the published privacy process. Independent legal review remains separate from product testing.
Independent review
Independent professional security, legal, and tax reviews remain explicit external follow-ups. Avori does not claim they are complete.