
AVEN
Security and data isolation
Server-side authorization filters organisation, client and project scope before search, export or automated processing context is assembled.
Layered safeguards
Isolate first, then process
- Organisation scope is resolved before client and project scope; broad roles remain broad only within the active organisation.
- Search, files, exports, reports and automated processing context reuse server-side effective permissions rather than relying on hidden buttons.
- Platform administrators do not receive default access to organisation business data; support access must be explicit, time-bound and audited.
- Licensed full-text standards remain in the organisation that supplied its licence basis; embeddings are not shared across organisations.
- Uploads use one scan, hash and version pipeline. Submitted and issued records remain append-only.
- Data export, retention and deletion follow an authorized workflow with a manifest and audit trail.
Multi-organisation access is invitation-only and is enabled only after the data-isolation gate passes. Public forms only create reviewable leads.
Transparency
Never send secrets through the public website
Public forms accept contact details and a high-level need only. Project files, keys, passwords and sensitive data belong in an authenticated, authorized channel.
Request a proposal
Start with the situation you actually have
Share your scope and the decision you need to make. Do not send sensitive project files through the public form.