Every call Avenora answers is encrypted, retained per policy, and attributable in our audit log. Here's what that means in practice.
TLS 1.3 for every call leg and every dashboard request. AES-256 at rest for transcripts, audio, and database tables. Keys rotated quarterly via a dedicated KMS.
Every cold-outreach number is scrubbed against the federal DNC + state DNC lists pre-dial, with calling hours validated against the prospect's local timezone. Demo calls you request from our site are different: they dial immediately because you asked for the call and gave express consent.
Emergency calls (gas, CO, no-heat-in-winter) retained 7 years for liability records. Non-emergency calls retained 1 year. Per-shop deletion on request.
Every call opens with a TCPA-compliant disclosure that recording is taking place and how to opt out. Disclosure language reviewed by an outside attorney quarterly.
Multi-tenant database with row-level security enforced at the Postgres layer. Customer dashboards cannot read another shop's data — even via misconfigured service tokens.
Every administrative action is timestamped and attributed. Founder-only access to production logs, with read-only audit replay available to customers on request.
We publish the status of every framework we're working through — no aspirational badges.
If you find something — anything — write to security@avenora.ai with reproduction steps. We acknowledge within 24 hours, fix in accordance with the severity, and credit responsible researchers in the changelog.
Email security@avenora.ai