Auvra Labs
Trust
Public trust center for security reviewers, buyers, and clients. This page summarizes how Auvra protects access, limits provider use, and keeps customer data out of public surfaces.
Version public_trust_2026-08-11_v5
Auvra Method
How Auvra qualifies, prepares, reviews, and measures revenue work before external actions.
Consent-Safe Outbound
How send readiness, suppression, approval, and channel-specific consent stay separate.
Integration Compliance
How official connectors, source review, automation hooks, and human approval stay separate.
Terms of Service
The operating terms for the Auvra console. The current version and effective date are shown on the page.
Privacy Policy
How Auvra handles account, workspace, telemetry, security, and provider data.
Subprocessors
The infrastructure, AI, billing, and email providers that support the service, by status.
Security Contact
Good-faith vulnerability disclosure contact and reporting expectations.
Operating controls
Tenant isolation
Enforced nowA signed-in user only sees workspace data after auth, MFA when required, legal acceptance when enforced, and workspace membership checks.
Provider gates
Enforced nowProvider calls run through workspace settings, active Lead Plan gates, spend ceilings, kill switches, and review queues.
Human approval
Enforced nowCRM writes, outreach, billing changes, and destructive operations stay behind explicit approval boundaries.
Product gates
Enforced nowSend eligibility, suppression, opt-outs, source allowed-use, and result claims are product gates, not just policy text. Auvra holds work when evidence or approval is weak.
Integration boundaries
Enforced nowAuvra separates official or reviewed source access from external execution. Source candidates, API exports, webhooks, and scheduled runs cannot approve terms, create contact intent, write CRM, send messages, or promote leads without the matching gate.
Do-not-contact override
Enforced nowA do-not-contact or legal-hold mark on a contact overrides every consent basis in the send-eligibility decision - no message can be judged eligible past it.
Error tracking
Built - not yet evidenced in productionServer error tracking with scrubbed telemetry is built into the app; it activates when the production error-tracking config is set, which is still an open launch item.
Certifications and attestations
PlannedSOC 2, ISO 27001, SAML SSO, SCIM, and a formal no-cross-client-training attestation are roadmap controls until verified evidence exists. Client data is tenant-scoped today, but the attestation is not yet a verified control.
Quiet-hours send windows
Not supportedTime-of-day send windows (quiet hours) are not a supported control yet - nothing sends today regardless, because outbound execution itself is gate-disabled.
Usage controls
Enforced nowUsage is tracked as Auvra credits and raw provider units without exposing internal markup or provider-cost accounting to company users.
Public authority
Enforced nowPublic pages explain Auvra's method and channel boundaries without exposing private workspace data or implying unsupported automation.
Current scope
Auvra prepares evidence-backed sales work for humans. External outreach, CRM writes, billing changes, provider execution, and destructive operations stay gated unless a future reviewed release explicitly enables the relevant action class.