Individual identity and scoped access
Users sign in individually. Household or organization memberships determine which connected resources a person may access. Requests derive their access scope on the server and fail closed when identity, membership, permissions, or configuration are missing.
Connected-account protection
Supported connections use provider authorization instead of collecting the provider account password. Application secrets and connection tokens stay in server-side systems. Sensitive credentials are encrypted at rest where stored and are excluded from chat responses and routine logs.
Approval before action
Consequential operations are separated into preparation and execution. The user reviews a specific proposed action before approving it. Confirmations are short-lived, bound to the person and resource, and protected against replay. Private fields such as vehicle PINs use a separate protected page rather than chat.
Data minimization and auditability
Product interfaces return selected fields needed for the request rather than raw provider responses. Security and activity records use safe metadata and avoid secrets. Precise vehicle location is isolated from routine status and is not included without an explicit request.
Current beta limits
The private betas use allowlists, feature flags, and controlled onboarding. Continuous Tesla telemetry and automatic vehicle commands are not active. Avery restricts external actions to registered handlers and approved workflows.
Report a security issue
Email info@hyperactiveautomation.com with a clear description and a safe way to reproduce the issue. Do not include passwords, access tokens, private keys, PINs, or sensitive third-party data. Please allow us a reasonable period to investigate before public disclosure.