Skip to main content

SECURITY

Business control stays with the owner.

Alvanate can prepare and run business workflows, but live authority remains explicit, scoped, time-bounded, and stoppable. No security program eliminates every risk, so incidents are recorded and live actions fail closed.

Scoped provider access

Connections receive only the permissions needed for approved workflows. Credentials stay server-side and encrypted.

Live-action controls

Publishing, customer actions, spending, refunds, and fulfillment pass approval, budget, provider-health, and consent gates.

Payment boundaries

Licensed providers handle card details, bank connections, payouts, and refunds. Alvanate does not store raw card numbers.

Evidence integrity

Actions, provider receipts, payments, refunds, costs, errors, and interventions remain attributable. Unverified revenue is never shown as confirmed profit.

Private references

Uploads are private, size-limited, scanned, and separated into observations and inferences before a change is proposed.

Account control

Users can end sessions, export data, request deletion, disconnect providers, and pause all external actions.

Incident response

High and critical incidents pause external actions automatically. Resuming requires a recorded reason and no unresolved high-severity incident.

Report a concern

Use Account settings to report an account incident or email alvanatehq@gmail.com. Do not include passwords or provider secrets.

Release status

Private founder validation is available. Public paid launch remains blocked pending legal identity and counsel review.

Security · Alvanate