Security & privacy

Your inspection records belong to you, and only your team can open them.

AvTools holds the photos, paperwork, and order data that back your shipments: the kind of records your customers and your quality system depend on. Here’s who can reach them, how they’re protected, and how you can check any of it for yourself.

Named accounts only

No shared logins, no guest access

Your data stays yours

Companies separated at the database

Always encrypted

In transit and at rest

Never trains AI models

Contractual, in our privacy policy

An audit trail you can read

Sensitive actions recorded on a best-effort basis

ERP access you control

You authorise it, you can revoke it

Access

Everyone who opens your records has a name.

No shared logins, no public links to your workspace, and no way for another company on AvTools to reach your data. Access starts with an account you created and a role you chose.

Who can open your records
  • People you've invited

    Your team, each with their own named account and password. You decide who joins and who leaves.

  • The roles you assign them

    Ordinary members see day-to-day work. Finance, admin settings, and AI features are restricted to admins, enforced on our servers, not just hidden in the menu.

  • Other companies using AvTools

    Every company's records are separated at the database level. Another company's account cannot reach your records, and that separation does not depend on the app asking nicely.

  • Anyone without an account

    The whole workspace requires signing in, including the photo files themselves. No public browsing, no shared team login, no guest access.

Foundations

The protections underneath every module

AvPics, QuoteDeck, Filing Assistant, paperwork, finance: these apply the same way across all of them.

Encrypted, coming and going

Everything is encrypted in transit, and your records and files are encrypted at rest by our infrastructure providers. That applies to every module, not just some of them.

Your company, walled off

Records carry the company that owns them, and the database enforces that on every read. Separation between companies is a property of the system, not a filter the app remembers to apply.

Credentials stay server-side

The keys connecting AvTools to your ERP live on our servers and are never sent to a browser or a phone. Settings screens show masked values only.

An audit trail you can read

Sensitive actions are written to audit trails: who, when, and what. AI reads are recorded on a best-effort basis so a logging outage does not block operational work, and authorized users can review the entries that were recorded.

Your photos & paperwork

What happens to an AvPics batch

Inspection photos are the most sensitive thing most customers put into AvTools. They show your parts, your customers' parts, and the condition of both.

Inspection photos

  • Photos live in private storage and cannot be opened without a signed-in account from your company, and there are no public photo links.
  • When the app shows you a photo, it checks that the photo belongs to your company, then serves it through a link that expires in minutes.
  • Photos our AI looks at are re-encoded first, which strips embedded camera metadata such as GPS coordinates.
  • Deleting a batch removes its photos from storage, not just from your view.

Generated paperwork

  • Sealed reports, signed documents, quote PDFs, and compliance evidence are held in private storage.
  • They're reached only through short-lived links that expire, and only after we've checked the request.
  • Files the AI assistant generates for you, such as spreadsheet exports and document copies, are deleted from storage on a fixed schedule: 30 days for exports, 7 days for document copies.
  • Sealed records carry a tamper-evident signature and an independent trusted timestamp.
  • The signing and audit trail is append-only: corrections are added, never quietly overwritten.
How sealed records work
Your ERP connection

We connect to your system on your terms

Linking AvTools to your ERP is the step customers scrutinise most, and rightly so.

See the connection guide
  • You authorise the connection yourself, through your ERP's own login. We never ask for your ERP password.
  • Your connection is used for your requests alone. A company without a connection gets a clean error, never a fall back to someone else's.
  • What we read through it is limited to what the features need, and you can narrow the integration account further on your side.
  • You can revoke it at any time, from your ERP or from your settings, and access stops immediately.
AI features

If you turn on the AI, the same boundary applies

AI is one optional module, off by default for every company and switched on deliberately. When it is on, it works inside the same walls as everything else, and it reads rather than acts.

Set before the assistant starts
01
You sign in

Your account identifies you and your company.

02
Your workspace is set

Established on our servers, from your account.

03
The assistant is assembled

Every tool it can reach is scoped to your company first.

04
It gets to work

Your orders, your parts, your photos. Only ever yours.

What this means for you: the assistant works inside your company’s data from the moment it starts. That comes from your login, so it holds for every question, every person on your team, and every day, without anyone having to remember to set it.

It reads. It doesn't change anything.

The assistant can look things up in your ERP. It cannot create, edit, or delete records there, and it has no way to send email or move your data elsewhere.

Nothing runs without you.

When it suggests an action on your device (printing labels, starting a batch) you get a confirmation prompt. It never acts on its own.

AI access is recorded.

The platform attempts to write an entry for each read: who asked, when, and which tool. Logging is best-effort and does not block your work if it fails. Entries contain metadata only, never file contents or the text of your questions.

Our commitments

What we will and won't do with your data

Your data never trains an AI model

Not ours, and not our AI provider's. It's contractual with our provider and written into our privacy policy, not a setting that could quietly change.

We don't mine it either

No advertising, no resale, no digging through your records for insights we can sell back to you. Any industry benchmark we publish is aggregated across customers and de-identified first, never drawn from so few companies that yours could be worked back out of it, and never with your name on it without your say-so.

Named subprocessors

Every third party that can touch customer data (hosting, database, AI provider, email, error monitoring) is named publicly in our privacy policy rather than buried in a contract.

You can take your data with you

Photos, batches, and generated paperwork are exportable, and you can revoke our ERP connection from your own system at any time. Nothing here is designed to trap you.

Need this in writing for a vendor review?

Send us your security questionnaire and we’ll fill it in. If your IT team would rather ask directly, we’ll set up a call with the people who built the platform.