Security

Designed for client-owned data from the start.

Avoras should make tenant isolation, signed provisioning, session boundaries, and auditability visible product strengths.

Security boundary diagram for Civxis signed provisioning and Avoras tenant isolation

Tenant-scoped data access is enforced server-side.

Civxis-to-Avoras provisioning is signed, timestamped, and idempotent.

Payment provider secrets stay in Civxis backend services.

Browser sessions use HTTP-only cookies; mobile uses bearer-session foundations.

Operational setup and workflow actions are designed for audit trails.