Security at Aitora
We treat access to organizational data as a scoped responsibility, not a default entitlement.
Last updated September 30, 2026
Working with design partners
Aitora is currently focused on design-partner diagnostics for sales and marketing workflows. Before any business system is connected, the purpose, data scope, access method, and people involved should be agreed with the organization.
Do not send passwords, API keys, access tokens, customer records, or other secrets through the public website form.
How access should be handled
Minimum necessary access
Request only the systems and information needed for the agreed diagnostic.
Clear scope
Document what will be reviewed, why it is needed, and who is authorized.
Evidence with boundaries
Use organizational data only for the agreed investigation and findings.
Controlled sharing
Limit findings and source evidence to the people approved to receive them.
Prompt removal
Remove access and unneeded working data when the agreed work is complete.
Forms and third parties
Website form submissions are processed and stored through Netlify Forms. Website usage is measured with Google Analytics. These providers maintain their own security and privacy practices.
A production engagement may require additional security, confidentiality, and data-processing terms based on the systems and information involved.
Security concerns
If you believe you found a security issue involving Aitora, email info@aitora.io with a clear description and steps to reproduce it.
Please do not publicly disclose an unresolved issue or access information that does not belong to you.