Skip to content

Security at Afora

Effective date: July 10, 2026 · Last updated: August 29, 2026 · Version 2.0

Afora gives you an AI agent with real access — to a machine of its own, and to the accounts you choose to connect. That makes isolation and credential handling the heart of our security work. This page describes, plainly, how we protect your data. Questions or concerns: security@aforademo.com.

Tenant isolation — one customer, one instance

Encryption and credentials

Infrastructure and subprocessors

The web app runs on Vercel; agent instances run on Hetzner cloud servers in the EU (Germany); the application database is Supabase; authentication is Clerk; billing is Stripe. Each vendor is listed with its purpose on our Subprocessor list, maintains its own independent security program, and is bound by contract to use customer data only to provide its service to Afora.

AI data handling

Agent action safety

An agent that can act is an agent that can be attacked through what it reads. We treat that as a first-class design constraint:

Compliance posture

We are a small team and we describe our posture honestly:

Data durability and retention

Incident response

We maintain a written incident-response plan. If an incident affects your data, we will notify you without undue delay — within 48 hours of confirmation for personal-data breaches — with what we know, what we've done, and a contact who can answer questions.

Reporting a vulnerability

We welcome good-faith security research. Report issues to security@aforademo.com (or see /.well-known/security.txt). Include steps to reproduce; we will acknowledge within 3 business days, keep you informed, and not pursue legal action for good-faith research that respects user privacy and avoids service disruption. Please do not access data that isn't yours or degrade the service. No bug bounty is offered at this time; we credit reporters who want it.