AVSBL uses layered protections across published websites, customer accounts, data, files, integrations, billing and recovery. These controls work together while customers remain responsible for protecting their own access and publishing accurate, appropriate content.
Managed HTTPS and browser protections
Published AVSBL websites use managed HTTPS so information is encrypted while travelling between the visitor and the website. AVSBL also applies secure browser headers, including transport protection, content restrictions, anti-framing controls, content-type protection and limited browser permissions.
The website engine generates safe published output and is maintained as browser and platform requirements change. Customer content and supported integrations can still affect an individual website, but customers do not need to configure the normal HTTPS or browser-protection layer themselves.

Account and customer-data separation
Customer websites, projects, drafts, published content, leads, analytics and billing records are kept within the owning customer account. Multiple layers of authorisation help prevent one customer from reading or changing another customer’s information.
Private dashboard reports use expiring, revocable links and are blocked from search indexing. Public website content is deliberately separated from private builder, lead, billing and account information.

Forms, requests and uploads
Forms and other sensitive requests are checked against the correct website, expected information and owning customer account. AVSBL also applies safeguards against invalid or excessive automated requests before accepted information is stored.
Image uploads are checked by declared type, decoded content, dimensions and file limits before they are processed into optimised website versions. Stored assets remain private unless an authorised published website references the approved output.

Integrations and connected providers
Supported provider connections use protected authorisation flows where available. Provider credentials are encrypted server-side, secrets are not included in published pages and redirect destinations or embedded provider origins are validated against the supported integration rules.
Connected email imports only messages matched to an AVSBL website enquiry. Each external provider remains responsible for its own accounts, availability, policies and security, while the customer controls whether the connection remains enabled.

Stripe and payment boundaries
AVSBL uses Stripe-hosted Checkout and the Stripe Billing Portal for Website Pro payment collection, so full card details are not entered into or stored by AVSBL. Stripe-confirmed payment events and AVSBL account records control billing changes and website access.
A customer’s connected Stripe commerce account is separate from the AVSBL Website Pro subscription. Stripe remains the payment provider, and its account access, transaction processing, fees and provider controls remain subject to the customer’s Stripe relationship.

Daily and monthly recovery backups
An automated recovery workflow creates a full production database backup and archives uploaded website assets every day. Daily recovery copies are retained for 30 days, and a separate monthly copy is retained for 365 days.
The recovery copies are encrypted and stored separately from the live database and website asset storage. AVSBL does not count the live services themselves as independent recovery backups.

Backup integrity and controlled restore testing
The recovery workflow checks that each database and website asset backup was created successfully and can be read. Integrity checks and recovery records help identify incomplete or damaged copies.
Controlled restore testing is performed away from the live production website first. A restore test must confirm that the database and referenced website assets work together before a recovery copy is treated as proven.

Customer responsibilities and limitations
No online service can eliminate every possible risk or promise uninterrupted availability. Backups are a recovery safeguard, not an instant self-service rollback or a guarantee that every external provider can be restored by AVSBL.
Customers are responsible for protecting account and domain access, using strong unique credentials, securing connected provider accounts, choosing trusted integrations, reviewing authorised users and keeping published information lawful and accurate. Suspected account compromise, unexpected provider activity or important data concerns should be reported to AVSBL support promptly.
AVSBL continually maintains and tests its supported platform controls, while third-party providers remain responsible for their own services and customers remain responsible for the access and content they control.
