Your inspection records belong to you, and only your team can open them.
AvTools holds the photos, paperwork, and order data that back your shipments: the kind of records your customers and your quality system depend on. Here’s who can reach them, how they’re protected, and how you can check any of it for yourself.
No shared logins, no guest access
Companies separated at the database
In transit and at rest
Contractual, in our privacy policy
Sensitive actions recorded on a best-effort basis
You authorise it, you can revoke it
Everyone who opens your records has a name.
No shared logins, no public links to your workspace, and no way for another company on AvTools to reach your data. Access starts with an account you created and a role you chose.
- People you've invited
Your team, each with their own named account and password. You decide who joins and who leaves.
- The roles you assign them
Ordinary members see day-to-day work. Finance, admin settings, and AI features are restricted to admins, enforced on our servers, not just hidden in the menu.
- Other companies using AvTools
Every company's records are separated at the database level. Another company's account cannot reach your records, and that separation does not depend on the app asking nicely.
- Anyone without an account
The whole workspace requires signing in, including the photo files themselves. No public browsing, no shared team login, no guest access.
The protections underneath every module
AvPics, QuoteDeck, Filing Assistant, paperwork, finance: these apply the same way across all of them.
Encrypted, coming and going
Everything is encrypted in transit, and your records and files are encrypted at rest by our infrastructure providers. That applies to every module, not just some of them.
Your company, walled off
Records carry the company that owns them, and the database enforces that on every read. Separation between companies is a property of the system, not a filter the app remembers to apply.
Credentials stay server-side
The keys connecting AvTools to your ERP live on our servers and are never sent to a browser or a phone. Settings screens show masked values only.
An audit trail you can read
Sensitive actions are written to audit trails: who, when, and what. AI reads are recorded on a best-effort basis so a logging outage does not block operational work, and authorized users can review the entries that were recorded.
What happens to an AvPics batch
Inspection photos are the most sensitive thing most customers put into AvTools. They show your parts, your customers' parts, and the condition of both.
Inspection photos
- Photos live in private storage and cannot be opened without a signed-in account from your company, and there are no public photo links.
- When the app shows you a photo, it checks that the photo belongs to your company, then serves it through a link that expires in minutes.
- Photos our AI looks at are re-encoded first, which strips embedded camera metadata such as GPS coordinates.
- Deleting a batch removes its photos from storage, not just from your view.
Generated paperwork
- Sealed reports, signed documents, quote PDFs, and compliance evidence are held in private storage.
- They're reached only through short-lived links that expire, and only after we've checked the request.
- Files the AI assistant generates for you, such as spreadsheet exports and document copies, are deleted from storage on a fixed schedule: 30 days for exports, 7 days for document copies.
- Sealed records carry a tamper-evident signature and an independent trusted timestamp.
- The signing and audit trail is append-only: corrections are added, never quietly overwritten.
We connect to your system on your terms
Linking AvTools to your ERP is the step customers scrutinise most, and rightly so.
- You authorise the connection yourself, through your ERP's own login. We never ask for your ERP password.
- Your connection is used for your requests alone. A company without a connection gets a clean error, never a fall back to someone else's.
- What we read through it is limited to what the features need, and you can narrow the integration account further on your side.
- You can revoke it at any time, from your ERP or from your settings, and access stops immediately.
If you turn on the AI, the same boundary applies
AI is one optional module, off by default for every company and switched on deliberately. When it is on, it works inside the same walls as everything else, and it reads rather than acts.
Your account identifies you and your company.
Established on our servers, from your account.
Every tool it can reach is scoped to your company first.
Your orders, your parts, your photos. Only ever yours.
What this means for you: the assistant works inside your company’s data from the moment it starts. That comes from your login, so it holds for every question, every person on your team, and every day, without anyone having to remember to set it.
It reads. It doesn't change anything.
The assistant can look things up in your ERP. It cannot create, edit, or delete records there, and it has no way to send email or move your data elsewhere.
Nothing runs without you.
When it suggests an action on your device (printing labels, starting a batch) you get a confirmation prompt. It never acts on its own.
AI access is recorded.
The platform attempts to write an entry for each read: who asked, when, and which tool. Logging is best-effort and does not block your work if it fails. Entries contain metadata only, never file contents or the text of your questions.
What we will and won't do with your data
Your data never trains an AI model
Not ours, and not our AI provider's. It's contractual with our provider and written into our privacy policy, not a setting that could quietly change.
We don't mine it either
No advertising, no resale, no digging through your records for insights we can sell back to you. Any industry benchmark we publish is aggregated across customers and de-identified first, never drawn from so few companies that yours could be worked back out of it, and never with your name on it without your say-so.
Named subprocessors
Every third party that can touch customer data (hosting, database, AI provider, email, error monitoring) is named publicly in our privacy policy rather than buried in a contract.
You can take your data with you
Photos, batches, and generated paperwork are exportable, and you can revoke our ERP connection from your own system at any time. Nothing here is designed to trap you.
Need this in writing for a vendor review?
Send us your security questionnaire and we’ll fill it in. If your IT team would rather ask directly, we’ll set up a call with the people who built the platform.