Where your data actually lives
Specifics rather than assurances. This describes the infrastructure as built, and it is deliberately verifiable against what you can observe from outside.
What's yours and what's ours
Yours: the phone number, the ad account, the CRM, your customer data, every lead record and every call log. These are created in your name, stay in your name, and you can export them at any time. Cancelling does not hold them hostage.
Ours: the automation layer that connects them — the workflows, prompts, and tooling. That is Averon's platform, licensed to you while you are a client, in the same way a CRM licenses you its software without handing over its source code.
What happens on the way out
The system integrates into your stack rather than replacing it, so cancelling is a disconnection, not a migration. We unhook the integrations, the automations stop, and your phone, CRM, calendar and ad account keep working exactly as they did before — carrying every contact and every call record added while we were live.
What does not come with you is the automation layer. Nothing of yours is withheld and there is nothing to untangle, but there is also no version where the machine keeps running without the subscription. Said here rather than at the exit, because a switching cost a client discovers late is the thing that makes this whole category distrusted.
The governing terms are in the MSA, not on this page.
Where things are stored
- Leads — Amazon DynamoDB in
us-east-1, encrypted at rest, with point-in-time recovery enabled. Kept as business records. - Site assistant conversations — a separate table with a 90-day automatic expiry. A chat transcript has no value after a few weeks and holding visitor conversations indefinitely is a liability, not an asset.
- Alert email — Amazon SES on a dedicated sending subdomain, so it cannot interfere with your existing mail records.
How access is limited
- Each function holds the narrowest IAM permission that lets it work — the assistant can write a lead and cannot read anyone else's.
- The AI model is scoped to one specific model. A blanket permission would let a compromised function invoke every model in the account.
- The assistant endpoint accepts requests only from registered site origins, so a third-party page cannot impersonate your business or spend your budget.
- Deployments authenticate with short-lived OIDC tokens. There are no long-lived cloud access keys to leak.
What the assistant will not do
It answers only from content approved in writing, refuses to quote prices or terms it was not given, and is instructed to say it does not know rather than guess. On any site whose visitors may discuss minors, contact capture is disabled at the infrastructure level rather than by instruction — because a prompt is guidance, not a control.
What we do not do
- We do not sell, rent or share your customer data. There is no third party in this pipeline that gets a copy.
- We do not ask for card numbers, health records, or government identifiers. If your business handles regulated data, that is a scoping conversation before any build, not an afterthought.
- We do not claim a certification we do not hold. There is no SOC 2 report for this business, and you should be suspicious of a solo operation that says otherwise.
Verify some of this yourself
Response headers on this domain show HSTS, a content security policy, frame denial and MIME-type protection. Page speed is measurable with Google's own tool. Those are the parts you can check without taking our word for anything — the homepage invites you to.
Ask the security questions on the call
If your business has data constraints, raise them before anything is built. It is much cheaper than raising them after.
30 minutes. No pitch deck. If we're not a fit we'll say so on the call.
Grab a slot — thirty minutes, your numbers, no deck.
Loading the calendar…