Website security and data handling
Understand what the public website does and what needs to be agreed for a separate engineering engagement.
Website data
This website uses HTTPS. Project-enquiry details are processed by a server endpoint and stored in Cloudflare D1 so the request can be reviewed.
These safeguards describe this public website. The ERP interfaces shown elsewhere are internal project concepts, not evidence of customer deployments or tenant isolation.
- HTTPS for website requests
- Server-side form validation
- Bot verification before accepting production submissions
- Hashed addresses and request limits for abuse prevention
Hosting and delivery
The public website is hosted on Cloudflare Workers. Its enquiry database and email integration are configured for this website.
Customer hosting, residency and access requirements must be agreed for each engagement; this page does not claim an existing customer VPC or production ERP deployment.
- Public website delivered through Cloudflare
- Enquiry records stored in Cloudflare D1
- Response headers restrict framing and browser resource access
- Automated checks cover the website build and submission controls
Scope and assurance
This page describes website behavior. It does not certify a customer system or establish suitability for a regulated workload.
Assurance documentation
No SOC 2 report or independently audited control set is presented here. Discuss required evidence before agreeing an engagement.
Personal data
The privacy policy describes the data requested by this website and how to contact us about it. An engagement may require separate data-processing terms.
Engagement requirements
Agree applicable privacy, residency and access requirements for the proposed work before sharing customer data.
Access boundaries
This website does not offer customer login or self-serve ERP accounts. Public forms accept enquiries; they do not provide access to stored enquiries.
Repository, infrastructure and customer-data access for engineering work must be scoped separately. No organization-wide MFA, access-review or audit-log coverage is asserted here.
- No self-serve product account on this website
- Project access agreed for the work in scope
- No public endpoint for listing enquiry records
- Do not put passwords or customer datasets in enquiry forms
Reporting a security concern
Use the contact below to report a concern about this website. Include enough information for us to understand the affected page or behavior.
Do not send secrets or another person’s data. This page does not claim an audited incident-response program or a guaranteed response time.
- Identify the affected page or function
- Describe the steps and observed behavior
- Explain the potential impact without exploiting other users
- Share only the minimum information needed
Security questions?
For website security questions or vulnerability reports, contact security@aatvi.ai.