Security & trust

We treat your data as our own

Security isn't an afterthought patch — it's the premise we design the service on. Here's how we protect your data, keys and access.

Keys not stored raw

API keys are shown in full only once at creation and stored encrypted; model keys come from session and system key management, never written into code repos.

Encrypted in transit & at rest

External traffic is TLS-encrypted; sensitive credentials stored encrypted. Access is granted least-privilege, with audit logs.

Identity & login

Login is handled by a professional identity service (Clerk) supporting strong authentication; customer and internal permissions are physically isolated to reduce privilege risk.

Sovereign compute first

Core capabilities run first on our own compute nodes; sourced capabilities are shown transparently under the Aolva brand, with clear, controllable data paths.

We don't monetize your private content

Your inputs and outputs are used to fulfill your request. By default we don't use your private content for public purposes or training; separate consent is sought for improvement.

Incident response

On a security incident, we notify affected users and regulators within a reasonable time per applicable law, and explain the measures taken.

Transparency

We believe "if it doesn't run, it really isn't connected"

The workbench and backend are designed not to gloss over: whether something is connected, how much was used, how much it cost — all shown truthfully. Usage and bills are clear, no hidden fees. Data handling details are in the Privacy Policy; terms in the Terms of Service.

Report an issue

Found a security issue? Tell us privately

Please don't disclose publicly. Email [email protected] and we'll respond as soon as possible.