We use a small number of cookies to run this site and to count page views. Choose Accept all to allow the optional ones, or Accept essential for only what the site needs. You can change your choice at any time. Learn more

Aiome
Products
Team chatChannels, threads, and direct messages Projects & tasksLists, boards, owners, and due dates SOPs & trainingDocument how the business runs Time offRequests, balances, and team coverage Time trackingClock in, timesheets, and approvals People & orgDirectory, roles, and org chart
See all features Compare plans Talk to sales
Our roadmapWhat we're building next Knowledge baseGuides, how-tos, and answers
Pricing Contact
Login Start free
Team chat Projects & tasks SOPs & training Time off Time tracking People & org See all features
Our roadmap Knowledge base
Pricing Contact Login Start free

Security at Aiome

Last updated August 9, 2026 Aiome Systems LLC
Contents
1. Our approach 2. Infrastructure 3. Encryption 4. Access control 5. Our own access 6. Vendor management 7. How we build 8. Certifications — candidly 9. Incident response 10. What we don't do 11. Report a vulnerability 12. For procurement teams

1.Our approach

Aiome holds information a team would not want made public — internal conversations, project plans, and records about its people. We treat that as the starting point rather than an afterthought.

We would rather state exactly where we are than imply more. Aiome is an early-stage company. This page describes the controls we actually operate today and, in Section 8, the ones we do not have yet. If you are evaluating us for a security review, that Section is the one to read first.

2.Infrastructure

Aiome runs on managed cloud infrastructure operated by established providers rather than on servers we rack ourselves. Our application is hosted on Vercel, and our database, file storage, and authentication are provided by Supabase, in its West US (Oregon) region. Both operate in the United States. Every provider is listed on our Subprocessors page.

Physical security, network security, hardware lifecycle, and data center operations are the responsibility of those providers, each of which maintains its own certifications and controls. We inherit those protections and layer our own on top.

Availability and backups. The Service runs on redundant, managed infrastructure. Our database provider takes automated, encrypted backups on a rolling cycle and restoration is performed through that provider's tooling; we do not maintain a separate restore process of our own, and we will not describe one we do not have. We also do not currently offer a contractual uptime commitment or service level agreement, and we state that rather than implying one.

3.Encryption

WhereHow
In transitTLS 1.2 or higher on all connections, with HTTP Strict Transport Security enforced. Plain HTTP requests are redirected to HTTPS.
At restAES-256 for the database, file and attachment storage, and backups.
Between servicesAll internal traffic between application, database, and storage is encrypted in transit.
CredentialsPasswords are never stored in plain text. Authentication secrets and API keys are held in managed secret storage, never in source code.

4.Access control in your workspace

  • Workspace isolation. Every table in our database has row-level security switched on and set to deny by default, scoped to your workspace. A request authenticated for one workspace cannot reach another's data, because the database itself refuses — not because the application remembers to ask. Permission changes are gated by an automated test suite of around 250 checks that attempts cross-workspace access from every angle we have thought of, and must pass before those changes ship.
  • Roles and permissions. You control who is a member, who is an administrator, and what each role can reach. Sensitive areas are narrower still: a free-text note on a time off request is visible only to the person who wrote it, your administrators, and the people you have designated to approve that leave — being someone's manager does not by itself grant access.
  • Authentication. Sign-in uses a one-time code sent to a verified email address.
  • Removing someone. Deactivating a member cuts off their access to your workspace immediately at the database layer, including to content they created themselves — it does not wait for a session to expire.

Worth knowing: administrators you designate can access, export, and delete content across your workspace, including content created by other members. That is a property of the tool, not a defect — but you should choose administrators deliberately and tell your team who they are.

What we do not offer yet. There is no single sign-on (SAML) and no way for you to require multi-factor authentication across your workspace. These are the two controls enterprise buyers ask us for most often, and we would rather list them as gaps here than let you find out during a security review. If either blocks a decision for you, tell us — that is what moves it up the roadmap.

5.Our own access to your data

Aiome personnel do not routinely access the contents of customer workspaces. Access occurs only when it is necessary to operate the Service, investigate a fault, respond to a support request you have made, or comply with law.

  • Access is limited to personnel who need it, on a least-privilege basis.
  • Administrative accounts require multi-factor authentication.
  • Changes to a time entry are recorded in an append-only audit trail showing who made the change, what changed, and any reason given. We do not currently keep a general access log covering every read of customer content, and we will not claim one.
  • All personnel are bound by written confidentiality obligations that survive the end of their engagement.
  • Production data is not used in development or testing environments.

6.Vendor and subprocessor management

Every vendor that processes data on our behalf is assessed before engagement and bound by a written agreement imposing data protection obligations no less protective than those we owe you. We remain fully liable to you for their performance.

Our complete list — what each does and where each processes data — is at Subprocessors. We give at least 30 days' notice before adding a new one that would process Customer Data, and you may object. See our Data Processing Addendum.

7.How we build

  • All code is version controlled, and changes are reviewed and tested before they reach production — including the automated workspace-isolation suite described in Section 4.
  • Development, preview, and production environments are separated.
  • Dependencies are scanned automatically for known vulnerabilities, and updates are reviewed and tested rather than merged blindly.
  • Secrets are managed outside source control and rotated when personnel or vendors change.
  • Infrastructure changes go through the same review as application code.

8.Certifications — candidly

Aiome does not currently hold a SOC 2 report, and we have not yet completed a third-party penetration test. We would rather state that plainly than let you discover it midway through a security review.

The following is exactly where we stand:

ItemStatus
GDPR / UK GDPRAddressed. We publish a DPA that auto-executes, incorporating the Standard Contractual Clauses and the UK Addendum.
US state privacy lawsAddressed. Service Provider terms and consumer rights procedures are in our Privacy Policy and DPA.
Encryption in transit and at restIn place.
Subprocessor governanceIn place, with a published list and 30-day change notice.
Breach notification processIn place — 72-hour customer notification commitment.
SOC 2 Type IINot yet. We are an early-stage company and have not begun an audit period. It is on our roadmap, and we will publish the dates here when an auditor is engaged rather than before.
Third-party penetration testNot yet. None has been carried out, and none is currently booked. We intend to commission one as the company grows, and will say here when it is done and by whom.
Cyber liability insuranceNot yet. We do not currently carry a policy. We expect to take one out as we take on larger customers.
HIPAANot supported. Aiome is not designed for protected health information and we do not offer a BAA.

If a certification is a hard requirement for your organization, tell us — knowing that it blocks a real deal is what moves it up the roadmap.

9.Incident response

We maintain a process for detecting, escalating, containing, and remediating security incidents, and the notification commitments below are contractual rather than aspirational.

If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within 72 hours, describing what we know, the likely consequences, what we are doing about it, and who to contact. Where the full picture is not yet clear, we send what we have and follow up rather than waiting.

We will not publicly identify an affected customer without their consent unless legally required. Our full commitments are in Section 10 of the DPA.

10.What we don't do

Sometimes the absence of a practice matters more than the presence of one:

  • We do not sell your data. Not to advertisers, data brokers, or anyone else.
  • We do not train AI on your data. As of today no Customer Data is sent to any AI or language model provider at all. If that changes, you get 30 days' notice, an administrator control, and a contractual prohibition on training. See Privacy Policy §6.
  • We do not surveil your employees. Time tracking records start and stop times. No screenshots, no location, no keystroke logging, no activity scoring. We designed it that way and our Acceptable Use Policy prohibits customers from using Aiome for unlawful monitoring.
  • We do not require a reason for time off. No one has to disclose a medical detail to request a day away.
  • We do not read your messages except where necessary to operate the Service or respond to a request you made.
  • We do not use dark patterns to keep you. Cancellation is a couple of clicks in your billing settings, with no retention gauntlet. See our Refund and Cancellation Policy.

11.Report a vulnerability

If you have found a security issue in Aiome, please tell us at aiome.io/contact or [email protected], with a description and steps to reproduce.

We will not pursue legal action against researchers acting in good faith who avoid privacy violations and service disruption, access only the minimum data needed to demonstrate an issue, do not exfiltrate or retain customer data, and give us reasonable time to fix it before disclosing publicly. Please test against a free workspace you create yourself, never against another customer's.

We aim to acknowledge reports within two business days.

12.For procurement and security teams

Everything we can share is on this site and designed to be read without contacting us:

  • Data Processing Addendum — auto-executes on signup, no signature needed. Annex II lists our technical and organizational measures in the format security reviews expect.
  • Subprocessor list — separated into vendors that can reach workspace content and vendors that cannot.
  • Privacy Policy — including the controller/processor split and a section written specifically for employees whose employer signed them up.
  • Acceptable Use Policy — including our restrictions on workplace monitoring.

Every page here prints cleanly to PDF if you need to attach one to a review file.

If you have a security questionnaire, send it to aiome.io/contact. We will complete it honestly, including the questions where the answer is "not yet."

Related documents: Data Processing Addendum · Subprocessors · Privacy Policy · Acceptable Use Policy

Aiome

The all-in-one workspace that brings your team — and every tool it runs on — into one place.

Product Team chat Projects & tasks SOPs & training Time off Time tracking People & org Features Pricing
Company Contact Talk to sales
Get started Start free Compare plans
Legal Privacy Policy Terms of Service Data Processing Addendum Subprocessors Security Acceptable Use Refunds & Cancellation Accessibility
© 2026 Aiome Systems LLC. All rights reserved. Aiome Systems LLC · 1401 21st St Ste R, Sacramento, CA 95811