Scoped provider access
Connections receive only the permissions needed for approved workflows. Credentials stay server-side and encrypted.
SECURITY
Alvanate can prepare and run business workflows, but live authority remains explicit, scoped, time-bounded, and stoppable. No security program eliminates every risk, so incidents are recorded and live actions fail closed.
Connections receive only the permissions needed for approved workflows. Credentials stay server-side and encrypted.
Publishing, customer actions, spending, refunds, and fulfillment pass approval, budget, provider-health, and consent gates.
Licensed providers handle card details, bank connections, payouts, and refunds. Alvanate does not store raw card numbers.
Actions, provider receipts, payments, refunds, costs, errors, and interventions remain attributable. Unverified revenue is never shown as confirmed profit.
Uploads are private, size-limited, scanned, and separated into observations and inferences before a change is proposed.
Users can end sessions, export data, request deletion, disconnect providers, and pause all external actions.
High and critical incidents pause external actions automatically. Resuming requires a recorded reason and no unresolved high-severity incident.
Use Account settings to report an account incident or email alvanatehq@gmail.com. Do not include passwords or provider secrets.
Private founder validation is available. Public paid launch remains blocked pending legal identity and counsel review.