🛡️ Trust Center — Last Updated September 2026

Security, Privacy & Compliance

We know enterprise buyers need more than promises. This page documents how Aidni handles your data, what controls are in place, and where we are on our compliance journey — with no overclaiming.

ActiveEnterpriseDesigned-ForIn Progress
⚠️
Certification vs. Design

We clearly distinguish Certified (formal third-party audit complete), Designed-For (controls in place, not yet certified), and In Progress (audit underway). We never claim certifications we haven't earned.

🔒 Data Security & Encryption

Data in TransitTLS 1.3 enforced on all network connectionsActive
Data at RestAES-256-GCM authenticated encryption for all stored credentials, tokens, and knowledge base vector partitionsActive
PII Token MaskingBidirectional regex engine redacts Credit Cards, SSNs, Aadhaar, PAN, emails and phone numbers prior to LLM inferenceActive
Vector Vault IsolationEach tenant's knowledge vectors are stored in isolated namespaces with row-level security (RLS)Active
API AuthenticationJWT-based bearer tokens with expiry and refresh rotationActive
Secrets ManagementCredentials encrypted at rest with AES-256-GCM; SMTP/IMAP passwords hashed before storageActive

🖥️ Infrastructure & Reliability

HostingSupabase (Postgres + pgvector) on AWS infrastructureActive
Uptime TargetContractual 99.9% SLA for Enterprise plans (with service credits); 99.5% target for self-serveActive
BackupsDaily automated database backups with 30-day retentionActive
CDNStatic assets served via Vercel Edge Network globallyActive
Enterprise VPCDedicated single-tenant AWS VPC with private subnet peering & isolated database tunnels on Enterprise plansEnterprise

🗄️ Data Handling & Retention

Customer Data UseYour uploaded documents and conversations are never used to train public AI modelsActive
Fair-Use Policy50,000 conversational AI messages/mo and 100k email campaign sends/mo on Enterprise; prevents abuse and guarantees low latencyActive
Data ResidencyPrimary data stored in AWS us-east-1; Enterprise plans can request region preferenceActive
Conversation LogsRetained for analytics and quality purposes; deletable via dashboard or APIActive
Data DeletionAccount deletion triggers full data erasure within 30 daysActive
Data ExportFull data export available on requestActive

✅ Compliance Posture

Designed-For, not Certified — see note above
GDPRArchitected around GDPR principles: data minimization, right to erasure, consent management, and sub-processor transparencyDesigned-For
HIPAAInfrastructure supports HIPAA-compatible configurations for Enterprise; BAA available on requestEnterprise
SOC 2SOC 2 Type II audit in planning phase; security controls in place and under reviewIn Progress
CCPAData subject rights (access, deletion, opt-out) supported via API and dashboardDesigned-For
ISO 27001Security controls align with ISO 27001 framework; formal certification not yet pursuedDesigned-For

👥 Access Control & Authentication

AuthenticationSupabase Auth with email/password and OAuth (Google, GitHub)Active
Role-Based AccessOwner, Admin, and Staff roles with granular permissions per chatbotActive
Staff IsolationStaff accounts can only access assigned agents — never owner billing or settingsActive
Session ManagementSession expiry, single-session enforcement, and forced logout availableActive
MFAMulti-factor authentication available via Supabase Auth (TOTP)Active

🤖 AI Models & Third-Party LLMs

Model ProvidersGoogle Gemini, OpenAI GPT, Anthropic Claude, and open-source models via OpenRouterActive
Data Sharing with LLMsConversation context is sent to LLM APIs for inference only; providers' data policies applyActive
Hallucination MitigationStrict knowledge grounding via RAG — agents answer only from uploaded documents; not 100% immuneActive
Prompt InjectionSystem prompt sandboxing and content filtering applied; actively monitoredActive
Model SelectionCustomers choose their preferred AI model per agent; no data used to fine-tune third-party modelsActive

🌐 Sub-Processors

ProcessorRoleRegionPrivacy
SupabaseDatabase, Auth, Storage, Vector SearchAWS (us-east-1)View →
VercelFrontend Hosting & Edge DeliveryGlobal CDNView →
OpenAILLM Inference (optional)US / EUView →
Google (Gemini)LLM Inference (optional)US / EUView →
AnthropicLLM Inference (optional)USView →
OpenRouterMulti-LLM Routing (optional)USView →
Twilio / WhatsAppWhatsApp Business Messaging (optional)US / GlobalView →
Resend / SMTPTransactional EmailUSView →

🚨 Incident Response SLAs

< 1 hourDetection & internal triage for critical severity issues
< 4 hoursInitial notification to affected enterprise customers
< 24 hoursPublic status update for platform-wide incidents
< 72 hoursGDPR breach notification to supervisory authority (if applicable)
< 7 daysFull post-mortem with root cause and remediation plan

Report security issues to security@aidni.io. We follow responsible disclosure and acknowledge all reports within 24 hours.

Need a DPA or Security Review?

Enterprise customers can request a Data Processing Agreement, security questionnaire, or a dedicated compliance call.

Contact Security Team →