Aitora.
Trust

Security at Aitora

We treat access to organizational data as a scoped responsibility, not a default entitlement.

Last updated September 30, 2026

Current stage

Working with design partners

Aitora is currently focused on design-partner diagnostics for sales and marketing workflows. Before any business system is connected, the purpose, data scope, access method, and people involved should be agreed with the organization.

Do not send passwords, API keys, access tokens, customer records, or other secrets through the public website form.

Principles

How access should be handled

  1. Minimum necessary access

    Request only the systems and information needed for the agreed diagnostic.

  2. Clear scope

    Document what will be reviewed, why it is needed, and who is authorized.

  3. Evidence with boundaries

    Use organizational data only for the agreed investigation and findings.

  4. Controlled sharing

    Limit findings and source evidence to the people approved to receive them.

  5. Prompt removal

    Remove access and unneeded working data when the agreed work is complete.

Website

Forms and third parties

Website form submissions are processed and stored through Netlify Forms. Website usage is measured with Google Analytics. These providers maintain their own security and privacy practices.

A production engagement may require additional security, confidentiality, and data-processing terms based on the systems and information involved.

Report

Security concerns

If you believe you found a security issue involving Aitora, email info@aitora.io with a clear description and steps to reproduce it.

Please do not publicly disclose an unresolved issue or access information that does not belong to you.