Auvra Labs
Auvra
Labs

Auvra Labs

Trust

Public trust center for security reviewers, buyers, and clients. This page summarizes how Auvra protects access, limits provider use, and keeps customer data out of public surfaces.

Version public_trust_2026-08-11_v5

Auvra Method

How Auvra qualifies, prepares, reviews, and measures revenue work before external actions.

Consent-Safe Outbound

How send readiness, suppression, approval, and channel-specific consent stay separate.

Integration Compliance

How official connectors, source review, automation hooks, and human approval stay separate.

Terms of Service

The operating terms for the Auvra console. The current version and effective date are shown on the page.

Privacy Policy

How Auvra handles account, workspace, telemetry, security, and provider data.

Subprocessors

The infrastructure, AI, billing, and email providers that support the service, by status.

Security Contact

Good-faith vulnerability disclosure contact and reporting expectations.

Operating controls

Tenant isolation

Enforced now

A signed-in user only sees workspace data after auth, MFA when required, legal acceptance when enforced, and workspace membership checks.

Provider gates

Enforced now

Provider calls run through workspace settings, active Lead Plan gates, spend ceilings, kill switches, and review queues.

Human approval

Enforced now

CRM writes, outreach, billing changes, and destructive operations stay behind explicit approval boundaries.

Product gates

Enforced now

Send eligibility, suppression, opt-outs, source allowed-use, and result claims are product gates, not just policy text. Auvra holds work when evidence or approval is weak.

Integration boundaries

Enforced now

Auvra separates official or reviewed source access from external execution. Source candidates, API exports, webhooks, and scheduled runs cannot approve terms, create contact intent, write CRM, send messages, or promote leads without the matching gate.

Do-not-contact override

Enforced now

A do-not-contact or legal-hold mark on a contact overrides every consent basis in the send-eligibility decision - no message can be judged eligible past it.

Error tracking

Built - not yet evidenced in production

Server error tracking with scrubbed telemetry is built into the app; it activates when the production error-tracking config is set, which is still an open launch item.

Certifications and attestations

Planned

SOC 2, ISO 27001, SAML SSO, SCIM, and a formal no-cross-client-training attestation are roadmap controls until verified evidence exists. Client data is tenant-scoped today, but the attestation is not yet a verified control.

Quiet-hours send windows

Not supported

Time-of-day send windows (quiet hours) are not a supported control yet - nothing sends today regardless, because outbound execution itself is gate-disabled.

Usage controls

Enforced now

Usage is tracked as Auvra credits and raw provider units without exposing internal markup or provider-cost accounting to company users.

Public authority

Enforced now

Public pages explain Auvra's method and channel boundaries without exposing private workspace data or implying unsupported automation.

Current scope

Auvra prepares evidence-backed sales work for humans. External outreach, CRM writes, billing changes, provider execution, and destructive operations stay gated unless a future reviewed release explicitly enables the relevant action class.

TermsPrivacySubprocessorsSecurity ContactSign in