Aveexia · legal information
Security and Trust
Last updated: 8 september 2026 · v2026-09-08
Security Philosophy and Architecture
Aveexia applies a defence-in-depth architecture where tenant isolation, least privilege and deterministic boundaries govern interactions between users, AI models and business systems. Security controls are integrated from the application layer to underlying data stores.
Infrastructure and Data Hosting
- Primary application services and background workers operate on European infrastructure (Render in Frankfurt, Germany / eu-central).
- Relational database services are hosted via Supabase in a Central Europe data centre (Zurich, Switzerland / eu-central-2).
- Real-time cache and queue coordination operate on Upstash Redis in a European zone (Frankfurt / eu-central-1) with TLS enabled.
- Frontend delivery and static assets are distributed via Vercel's edge network with DDoS mitigation and HTTPS termination.
Data Protection and Encryption
- Data in transit to public endpoints and web services is protected using HTTPS/TLS.
- Data at rest is protected using the encryption controls provided by the configured infrastructure services.
- Application logs are filtered and sanitized to redact credentials, API keys and sensitive customer fields before persistence.
Tenant Isolation
Organizations and workspaces are segregated through server-enforced authorization boundaries. Data access is validated at the application layer against the authenticated tenant, with PostgreSQL Row-Level Security (RLS) configured on core relations to reinforce separation. Cache keys and internal queues incorporate tenant scoping.
Access Control and Identity
- Role-based access control (RBAC) governing administrators, agents and operators within each customer workspace.
- Session management utilizing cryptographically validated tokens with defined expiration.
- The principle of least privilege is applied to internal operations and administrative roles.
AI Model Boundaries and Data Integrity
Customer data processed via AI capabilities is transmitted via API subject to the selected model configuration and provider terms. Aveexia minimizes payload data by supplying only necessary conversation context and relevant excerpts from approved knowledge sources. Responses are grounded in provided business materials, and actions with commercial or financial impact require explicit confirmation or human handoff.
Retention, Deletion and Backups
- Data retention is managed according to agreed periods and available account settings.
- Upon account termination or deletion requests, organization data is purged from primary application databases in accordance with documented procedures.
- Backup and recovery procedures are maintained across underlying relational database services to support operational continuity.
Incident Management and Responsible Disclosure
Aveexia maintains a documented incident response process covering detection, containment, investigation and prompt notification of supervisory authorities and affected customers without undue delay. Security researchers and customers can report potential vulnerabilities or incidents directly to legal@aveexia.com.
Factual Boundaries and Audits
We only make statements supported by our active production architecture. Aveexia does not claim third-party certifications (such as SOC 2 or ISO 27001) that have not been formally completed, and we never claim zero risk or 100% invulnerability. Security is an active, continuous discipline. Contact us for our complete architecture and security documentation.
Version and Contact
Document version 2026-09-08. For security inquiries, DPA execution or technical documentation, contact our security team at legal@aveexia.com.