Jugaar LLC
Security
Effective August 2, 2026
AVA Operator is designed so a Hub outage cannot stop calls. Signed offline licences gate management actions only; existing Agents keep answering. Recordings, transcripts and call history remain on operator-controlled infrastructure unless the operator deliberately exports them.
Operational boundaries
- Release manifests are signed and container references are pinned by digest.
- Installations use scoped credentials and fail closed when required production secrets are absent or placeholders.
- Managed PBX changes are explicit, journaled and designed to be reversible.
- AVA Operator v1 sends no call telemetry, health beacon or automatic support bundle to Jugaar.
Report a vulnerability
Email [email protected] with the affected surface, reproduction steps and likely impact. Do not include live credentials, unnecessary personal information, recordings or transcripts. If sensitive evidence is required, ask for a protected transfer method first.
Please avoid privacy violations, service disruption, destructive testing, social engineering and accessing data that is not yours. We do not currently offer a paid bug-bounty programme or promise a fixed response time, but we will acknowledge and investigate credible reports.
Account or operational incident
For a suspected compromised Installation, token or account, identify the affected Installation and contact security immediately. For ordinary setup or product support, use [email protected].
