A shared project space for proposals, milestones, decisions, messages, and files. Membership controls which project material a client can access.
A member signs in
An authorized email receives a time-limited, one-time sign-in code.
Permission is checked
The server checks active membership and whether the project is open.
The project is shared
Authorized members can access the project records and files stored encrypted in the database.
The boundary
An administrator manages membership. Removing membership or closing a project withdraws client access. Approval records identify the member and the version reviewed.
These controls describe the website and its client workspace. The design of a separately delivered client system is agreed for that engagement.
Encrypted content
Inquiry, workspace, and meeting content is encrypted in the website database using AES-256-GCM. Operational metadata such as identifiers, timestamps, statuses, and keyed lookup values remains available to run the service.
The service can decrypt content for authorized use. This is not end-to-end encryption.
Defined access
Administrator and client-workspace sign-in use separate sessions. The server checks authorization; project membership controls client access to project records and files.
Twelve-hour authentication cookies use Secure, HttpOnly, and SameSite=Strict attributes.
Decisions with context
Workspace writes check revisions and request identifiers to handle concurrent changes and duplicate requests. An approval records the member and the version reviewed.
A changed version requires a new review; it does not silently inherit an earlier approval.
A smaller public footprint
The public website has no advertising trackers or third-party analytics. An inquiry does not subscribe you to a marketing list, and the inquiry workflow does not send submissions to a generative AI model.
Hosting infrastructure still processes technical and security information needed to operate the service.
The infrastructure behind it.
Cloudflare provides hosting, network protection, the database, and email transport. Ordinary email is processed by the relevant mail providers. Those provider boundaries also apply to replies and accepted inbound email forwarded to the business mailbox.
Cleanup follows the record’s purpose and activity. Removing website records does not automatically remove copies in other systems.
365 days without activity
Website conversations
Daily cleanup removes conversations after 365 days without new activity. Incoming messages and newly recorded outgoing reply attempts restart the period. Reading or archiving does not extend it.
365 days after closure
Client projects
Open projects remain available. Closed project records and files are scheduled for daily cleanup after 365 days from closure. Reopening cancels that cleanup; revoking membership does not delete the project.
365 days after the later event
Meeting requests
Requests become eligible for cleanup 365 days after their last update or their confirmed meeting time, whichever is later. For an unconfirmed request, the latest requested time is used. Cleanup is batched.
Expired authentication and request-limiting records are also cleaned up. Separate mailboxes, infrastructure logs, backups, and engagement systems have their own retention processes.
A useful review starts with the work you intend to commission. Share your procurement checklist and the conditions that matter to your organization before project information is exchanged.
Identify the data categories, sensitivity, source systems, and people whose information may be processed. Establish what can be shared during discovery and what needs a separate channel or agreement.
The operating boundary
Agree who owns system accounts, who can approve access, which providers are permitted, and whether location or transfer requirements apply. Website hosting does not establish a data-residency commitment for an engagement.
The written commitment
Set deliverables, exclusions, client responsibilities, acceptance criteria, fees, and delivery dependencies in the services agreement. Address confidentiality and a data-processing agreement where appropriate.
The life after delivery
Define handover, support, access removal, retention, and deletion responsibilities. A pilot or discovery engagement does not automatically include ongoing hosting, maintenance, or future development.
PUBLIC COMPANY INFORMATION
Ayan LLC.
An applied AI and automation studio, operating under the Ayan brand.
30 N Gould St PMB 58667 Sheridan, WY 82801-6317 United StatesMailing address only.
USEFUL DISTINCTIONS
A few details worth making clear.
Can project data be shared through the initial form?
Use the initial inquiry for an appropriate business introduction. Do not send passwords, payment details, sensitive personal information, or confidential project documents. Agree the data boundaries and a suitable channel before sharing that material.
What if procurement requires specific assurance evidence?
Identify the certification, independent audit, insurance, contractual terms, or supporting documents your process requires. Confirm what evidence is available and what commitments can be agreed before treating a requirement as satisfied.
Does hosting establish where all data stays?
No. Providers may process information in more than one jurisdiction. If an engagement requires a particular data location or transfer arrangement, address it in the architecture and contract before data is shared.
How should a security concern be reported?
Email hello@withayan.com with “Security concern” in the subject. Describe the affected page and observed behavior, with enough context to investigate. Do not include credentials, secrets, or unrelated personal data.