Averon  //  AI Deployment Security Riyadh  ·  Data resident in KSA  ·  NCA-aligned reporting أمن أنظمة الذكاء الاصطناعي
Averon/Contact

Request an engagement.

Every engagement begins with a ninety-minute technical scoping session against your architecture. There is no commercial commitment, and no material needs to leave your environment for it to be useful.

Response
Acknowledgement
Within one business day
Scoping session
Riyadh, on your premises, or secure video
Language
Arabic or English
Confidentiality
Mutual NDA executed before technical detail is exchanged
Engagement request

Tell us what you are deploying.

Do not include sensitive architectural detail, credentials, or client data in this form. It is sufficient to describe the system in general terms; the technical exchange happens under NDA.

This form does not yet submit. Send the same information directly to admin@averon.systems, encrypted where appropriate.

Direct

Channels

We ask that no client data, architecture documentation, or credentials be sent by unencrypted email at any stage.

Encrypted correspondence

An encryption key for sensitive correspondence is provided on request, with the fingerprint confirmed out of band before anything is transmitted. Ask before sending material you would not send in the clear.

Responsible disclosure

If you have identified a security issue in Averon's own infrastructure, or in a system you believe we assess, write to admin@averon.systems. We acknowledge within one business day and will agree a disclosure timeline with you. We do not operate a bounty programme and we do not require you to accept non-disclosure terms in order to report.

Before you write

Questions worth answering internally first.

Not prerequisites. If you can answer these, the scoping session will be shorter — and if you cannot, that is itself a useful result.

  • Under what identity does your retrieval layer read from source systems?
  • Can the system return a document to a user who could not open that document directly?
  • Which tools can the model call, and which of those change state?
  • What is the ceiling on tool calls in a single conversation?
  • What happens when a document in your corpus contains instructions addressed to the model?
  • Where are prompts and completions logged, and who can read that store?
  • Who is permitted to register a new tool, and what review does that pass through?
  • When the model version last changed, what was re-tested?