Our commitment
We aim to use technical and organisational measures proportionate to the nature of Avo AI, the data processed and the risks involved. No online service can promise perfect security.
Security controls
Access control
Authentication, least-privilege access and periodic access review.
Data protection
Encryption in transit, data minimisation and controlled retention.
Development
Dependency management, review, testing and vulnerability remediation.
Monitoring
Logging, abuse detection and investigation of suspicious events.
Resilience
Backups, recovery planning and service-capacity controls.
Suppliers
Risk-based review and contracts for relevant service providers.
Account safety
Users should use a unique password, protect recovery emails and devices, avoid sharing credentials, and contact us promptly if an account may be compromised.
Report a vulnerability
We welcome good-faith reports about genuine security weaknesses affecting Avo AI itself. This policy does not authorise testing of customers, third-party providers or infrastructure we do not own.
Email support@avoai.co.uk with the affected page or feature, clear reproduction steps, potential impact and the minimum evidence needed to confirm the issue.
Research rules
- Use only accounts and data you own or are authorised to use.
- Do not access, alter or retain another person’s data.
- Avoid denial of service, social engineering, malware and high-volume automated testing.
- Stop and report immediately if sensitive data is encountered.
- Keep the issue confidential for a reasonable remediation period.
What to expect
We aim to acknowledge credible reports, investigate them, keep the reporter reasonably informed and prioritise remediation according to impact and likelihood. These are targets rather than contractual response times.
AI safety
AI output may be incorrect or unsafe in a particular context. Review important recommendations, code and instructions before using them, and never treat generated output as proof that something is secure or correct.
Contact
Security reports
Use a clear subject line and include only the information needed to reproduce the issue.