Trust & Compliance Center

Security, Privacy & Data Governance

How Aidora Labs protects client assets, handles external integrations, and ensures architectural integrity across our SaaS products and custom engineering engagements.

Last Updated: September 25, 2026 · Aidora Labs

100% IP Transfer & NDA

Mutual Non-Disclosure Agreement active on Day 1. Full assignment of custom source code, databases, and assets upon project completion.

Encrypted BYOK Architecture

Bring Your Own Key (BYOK) model for GrowthLens AI. User-provided API keys are encrypted at rest and never shared with third parties.

Scoped Google OAuth Access

Strictly read-only data access to Google Analytics & Search Console APIs. Zero access to unauthorized scopes or private accounts.

1. External Data Access (GrowthLens AI)

GrowthLens AI is an AI-powered website performance, SEO, and growth analytics platform developed by Aidora Labs. When you connect external data sources, we adhere to strict least-privilege access principles:

  • Google Search Console (GSC): GrowthLens connects via OAuth 2.0 with read-only permissions (https://www.googleapis.com/auth/webmasters.readonly). We fetch query impressions, clicks, click-through rates (CTR), and average keyword positions strictly to compute growth opportunities and generate audit reports.
  • Google Analytics 4 (GA4): Connects via read-only access (https://www.googleapis.com/auth/analytics.readonly) to assess session traffic, bounce indicators, and user engagement trends.
  • Zero Write Permissions: GrowthLens never requests write, modification, or deletion access to your Google Search Console properties or Google Analytics containers.
  • Google API Services User Data Policy: GrowthLens AI’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2. AI Model Providers & Data Processing

To generate plain-English SEO diagnostics and structured action plans, GrowthLens AI routes diagnostic summaries to verified AI model endpoints:

  • Supported AI Providers: Depending on configuration, GrowthLens leverages Google Gemini, OpenRouter, and OpenAI endpoints.
  • No Model Training: Your business search metrics, private query data, and website audit summaries are processed solely for the real-time generation of your specific diagnostic report. Data transmitted through official enterprise APIs is never used to train public foundational models.
  • Data Minimization: Only aggregated numerical metrics, URL paths, and keyword strings relevant to the analysis are sent to the AI processing layer. No customer personal identifiers (PII) are transmitted.

3. API Keys & Bring Your Own Key (BYOK) Security

GrowthLens AI offers a Bring Your Own Key (BYOK) option for customers who prefer using their own model provider accounts:

  • Key Encryption: When you provide your own API key (e.g., Google Gemini or OpenRouter), credentials are encrypted at rest using industry-standard AES-256 encryption.
  • Isolated Execution: API keys are decrypted only in secure server-side execution environments during report generation and are never logged in plaintext or exposed to frontend client bundles.
  • Revocation Control: You maintain complete autonomy to revoke or update your provider API keys at any time directly through your model provider dashboard.

4. Application & Infrastructure Security

Our web applications and SaaS backend services implement multiple layers of security controls:

  • Transit Encryption: All web traffic is strictly served over HTTPS with TLS 1.3 encryption and HSTS preloading to prevent interception.
  • Bot & Abuse Prevention: We utilize Cloudflare Turnstile and server-side rate limiting to prevent automated brute-force attacks and abuse across public endpoints.
  • Firestore & Database Security: Database schemas and backend rules enforce role-based access control, ensuring users can only read and modify their own project documents.
  • Input Validation & Sanitization: All user inputs and audit parameters undergo strict server-side validation using structured schemas to defend against injection and cross-site scripting (XSS).
  • Serverless Isolation: API routes execute in isolated serverless edge and Node.js environments with minimal runtime privileges.

5. Client Confidentiality & IP Protection

For bespoke software development and AI engineering clients:

  • Mutual NDA on Day 1: We execute a binding Non-Disclosure Agreement before any proprietary business workflows, architecture diagrams, or credentials are exchanged.
  • Full IP Ownership Transfer: All custom code, database designs, configuration scripts, and digital assets developed under contract are 100% transferred to the client upon milestone payment completion.
  • Dedicated Repositories: Client codebases reside in private, access-controlled repositories with granular permissions.

6. Vulnerability Reporting & Responsible Disclosure

We welcome responsible security research and value reports on potential vulnerabilities. If you discover a security concern regarding Aidora Labs or GrowthLens AI, please report it immediately to our engineering team:

Official Security & Compliance Contact

AIDORA LABS — Security Engineering Team

Location: Piduguralla, Andhra Pradesh, India

Business Identification: D-U-N-S Number 311069410

Security Email: support@aidoralabs.in