Security at Aviato

Connected operations.
Considered protection.

Your customers trust you with their data. See how Aviato handles access, credentials and the trace every action leaves.

Talk security with us
01Your workspace02Scoped access03Recorded actions
A connected operation. Clearly defined boundaries.Architecture illustration

Clear boundaries

Keep projects, environments and connections organised around your workspace.

Purposeful access

Give every person and every agent the scope it needs for the job, and nothing more.

Traceable operations

Keep a record of every change, from the request to its result.

Built into the connection

Small details. Meaningful safeguards.

A closer look at how Aviato handles data access, credentials and actions.

01

Your data stays where it is

The Aviato agent reads and writes your database directly. Run it next to your data, and your records never leave your infrastructure.

Data location
02

Encrypted credentials

When we host the agent for you, database credentials are encrypted at rest and only used by the agent serving your project. We recommend read-only users wherever possible.

Credential handling
03

One path for every change

Every change, whether it comes from your team, your code or an AI agent, goes through the same permission checks, approvals and audit trail.

Permission enforcement
04

An audit trail you configure

Choose what the audit trail keeps: full before-and-after values, field names only, or nothing at all for sensitive fields.

Event traceability

A closer look

Connected to your tools. Bound to a purpose.

Every request should have a defined place in your operation. Here’s how an action reaches your database through Aviato.

  1. 01

    Identify the caller

    Verify the person or agent, and the role it acts under.

  2. 02

    Check its permission

    Apply roles, row-level scopes and approval rules before anything runs.

  3. 03

    Record the result

    Run the action and add it to the audit trail.

Illustrative action flow
Person or agent01
Permission check
Aviato agent02
Action + audit record

What leaves your infrastructure

Your records stay with you. Here is exactly what moves.

Aviato is split in two. Only one part ever touches your database, and it runs where you decide.

Runs next to your database

The agent

The only component that connects to your database. It serves your data directly to the people and AI clients you authorize.

  • Self-hosted in your infrastructure, or in an isolated machine we run for you
  • Checks every request against short-lived tokens bound to one project and environment
  • Keeps an audit outbox and a decision cache on its own disk
Our cloud

The control plane

Accounts, projects, roles, SSO, billing, the audit trail and the approval queue. It never connects to your database.

  • Signs the tokens the agent verifies
  • Stores the audit trail, redacted the way you choose
  • Holds approval requests until they run or expire

By default

What moves on day one.

With no optional feature turned on, this is the complete list.

WhatFrom → toContains
Records you browse or editAgent → your browserOnly what your role may read. Never stored by Aviato.
Records an AI client reads through MCPAgent → the AI client you connectedOnly what the connecting person may read. The client’s own provider then processes it under your agreement with them.
SchemaAgent → control planeTable, field and relation names and types. No values.
HeartbeatAgent → control planeAgent version, uptime, audit backlog size, schema version and public URL.
Audit eventsAgent → audit trail (our cloud)Who did what, when and from where, the record id, and field changes according to your redaction mode.
Plugin callsAgent → your plugin codeStay in your infrastructure: the agent calls the URL you configure.

Redaction modes

You decide what the audit trail keeps.

Set per environment, in the project settings. Fields named like secrets, such as password or token, can be marked as always redacted.

Full

Field names with their before and after values, except the fields you mark as always redacted.

Default · Hosted agents

Field names only

Which fields changed, never their values.

Default · Self-hosted agents

None

Nothing but the event itself: who, what, when and which record.

Only when you turn it on

Optional features. Explicit data flows.

Each of these is off until you enable it, and sends only what is listed here.

FeatureWhat is sentWhere
Ask your dataYour question and the schema (names and types). Never record values: the answer is a query the agent runs.Control plane → the LLM provider (Anthropic).
AI decision fieldsFor each record decided, only the input fields you selected for that decision field. Results are cached in the agent.Agent → control plane → Jev (TypeSafe AI), or the LLM provider when Jev is unavailable. With your own Jev key, the provider bills you directly.
Risk checks on AI agents’ actionsThe action name and description, the selected record count or filter, and the form values.Agent → control plane → the same decision model as decision fields.
ApprovalsThe action, its target (ids or filter) and form values, encrypted at rest, until the request runs or expires.Agent → control plane.
Audit streaming and exportsAudit events, redacted as configured.Our cloud → your webhook or storage bucket.
Hosted agentYour database connection string, encrypted at rest. The agent itself runs in our infrastructure.Control plane. Choose a self-hosted agent to keep it on your side.

Hosted or self-hosted

Pick where the agent runs.

Start in minutes

Hosted

  • Paste a connection string, we run the agent in an isolated machine
  • The connection string is encrypted at rest in the control plane
  • Audit trail keeps full before and after values by default
Your infrastructure

Self-hosted

  • One binary or Docker image next to your database
  • Needs only outbound HTTPS to the control plane and audit ingest
  • Credentials never leave your side; audit trail keeps field names only by default

What never leaves

Some things stay put, whatever you enable.

  • Your database credentials, with a self-hosted agent
  • Record values in the schema, heartbeats or ask-your-data prompts
  • Values of fields a decision field does not list as inputs

Let’s get specific

Your requirements. A direct conversation.

Read our privacy policy
Evaluating Aviato for your security requirements?

Tell us about your data, identity, hosting and procurement requirements. We’ll walk through the hosted and self-hosted options before you connect your production systems.

Where can I learn about personal data?

Our privacy policy explains how we handle personal information. For questions about your specific data flow or processing requirements, contact our team.

How do I report a potential vulnerability?

Email our security team with the affected area, steps to reproduce and potential impact. Please avoid including customer data or secrets in your initial report.

Responsible disclosure

Help us make Aviato safer.

Found something we should investigate? Reach our security team directly.

[email protected]