Trust

Security

Last updated September 22, 2026

When you send us a problem, you might also send files your business considers sensitive. This page explains what happens to them.

Files you upload with a request

  • Private. Files go straight from your browser into a private storage bucket that has all public access blocked. Nothing about them is public, and the links used to upload them expire after a few minutes.
  • Encrypted. Files are encrypted in transit (TLS) and at rest with an encryption key AFT manages in AWS Key Management Service.
  • Deleted automatically. Uploaded files are deleted 180 days after upload. Ask us and we'll delete them sooner.
  • Not used for AI training. We never use your files or problem descriptions to train AI models.
  • Limited access. Only AFT staff working on your request can open your files.

Infrastructure

  • Hosted on Amazon Web Services in the United States.
  • HTTPS everywhere, with strict transport security and a restrictive content security policy.
  • The database of requests is encrypted with a customer-managed key.
  • Each AFT product runs on its own domain, with its own user accounts, so a problem in one product cannot reach another.
  • Rate limiting, monitoring and alerts on the request service.

Before you upload

Send only what we need to understand the problem. Remove or redact personal data, credentials and anything covered by export control (such as ITAR or EAR technical data) unless we have agreed a process for it in advance. If you need a confidentiality agreement before sharing details, ask us first.

Reporting a vulnerability

If you think you've found a security issue in the site or an AFT product, please email admin@advancedfoundrytech.com with "Security" in the subject. Please give us a reasonable chance to fix it before you disclose it publicly. We'll acknowledge your report and keep you updated.