Aiome holds information a team would not want made public — internal conversations, project plans, and records about its people. We treat that as the starting point rather than an afterthought.
We would rather state exactly where we are than imply more. Aiome is an early-stage company. This page describes the controls we actually operate today and, in Section 8, the ones we do not have yet. If you are evaluating us for a security review, that Section is the one to read first.
Aiome runs on managed cloud infrastructure operated by established providers rather than on servers we rack ourselves. Our application is hosted on Vercel, and our database, file storage, and authentication are provided by Supabase, in its West US (Oregon) region. Both operate in the United States. Every provider is listed on our Subprocessors page.
Physical security, network security, hardware lifecycle, and data center operations are the responsibility of those providers, each of which maintains its own certifications and controls. We inherit those protections and layer our own on top.
Availability and backups. The Service runs on redundant, managed infrastructure. Our database provider takes automated, encrypted backups on a rolling cycle and restoration is performed through that provider's tooling; we do not maintain a separate restore process of our own, and we will not describe one we do not have. We also do not currently offer a contractual uptime commitment or service level agreement, and we state that rather than implying one.
| Where | How |
|---|---|
| In transit | TLS 1.2 or higher on all connections, with HTTP Strict Transport Security enforced. Plain HTTP requests are redirected to HTTPS. |
| At rest | AES-256 for the database, file and attachment storage, and backups. |
| Between services | All internal traffic between application, database, and storage is encrypted in transit. |
| Credentials | Passwords are never stored in plain text. Authentication secrets and API keys are held in managed secret storage, never in source code. |
Worth knowing: administrators you designate can access, export, and delete content across your workspace, including content created by other members. That is a property of the tool, not a defect — but you should choose administrators deliberately and tell your team who they are.
What we do not offer yet. There is no single sign-on (SAML) and no way for you to require multi-factor authentication across your workspace. These are the two controls enterprise buyers ask us for most often, and we would rather list them as gaps here than let you find out during a security review. If either blocks a decision for you, tell us — that is what moves it up the roadmap.
Aiome personnel do not routinely access the contents of customer workspaces. Access occurs only when it is necessary to operate the Service, investigate a fault, respond to a support request you have made, or comply with law.
Every vendor that processes data on our behalf is assessed before engagement and bound by a written agreement imposing data protection obligations no less protective than those we owe you. We remain fully liable to you for their performance.
Our complete list — what each does and where each processes data — is at Subprocessors. We give at least 30 days' notice before adding a new one that would process Customer Data, and you may object. See our Data Processing Addendum.
Aiome does not currently hold a SOC 2 report, and we have not yet completed a third-party penetration test. We would rather state that plainly than let you discover it midway through a security review.
The following is exactly where we stand:
| Item | Status |
|---|---|
| GDPR / UK GDPR | Addressed. We publish a DPA that auto-executes, incorporating the Standard Contractual Clauses and the UK Addendum. |
| US state privacy laws | Addressed. Service Provider terms and consumer rights procedures are in our Privacy Policy and DPA. |
| Encryption in transit and at rest | In place. |
| Subprocessor governance | In place, with a published list and 30-day change notice. |
| Breach notification process | In place — 72-hour customer notification commitment. |
| SOC 2 Type II | Not yet. We are an early-stage company and have not begun an audit period. It is on our roadmap, and we will publish the dates here when an auditor is engaged rather than before. |
| Third-party penetration test | Not yet. None has been carried out, and none is currently booked. We intend to commission one as the company grows, and will say here when it is done and by whom. |
| Cyber liability insurance | Not yet. We do not currently carry a policy. We expect to take one out as we take on larger customers. |
| HIPAA | Not supported. Aiome is not designed for protected health information and we do not offer a BAA. |
If a certification is a hard requirement for your organization, tell us — knowing that it blocks a real deal is what moves it up the roadmap.
We maintain a process for detecting, escalating, containing, and remediating security incidents, and the notification commitments below are contractual rather than aspirational.
If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within 72 hours, describing what we know, the likely consequences, what we are doing about it, and who to contact. Where the full picture is not yet clear, we send what we have and follow up rather than waiting.
We will not publicly identify an affected customer without their consent unless legally required. Our full commitments are in Section 10 of the DPA.
Sometimes the absence of a practice matters more than the presence of one:
If you have found a security issue in Aiome, please tell us at aiome.io/contact or [email protected], with a description and steps to reproduce.
We will not pursue legal action against researchers acting in good faith who avoid privacy violations and service disruption, access only the minimum data needed to demonstrate an issue, do not exfiltrate or retain customer data, and give us reasonable time to fix it before disclosing publicly. Please test against a free workspace you create yourself, never against another customer's.
We aim to acknowledge reports within two business days.
Everything we can share is on this site and designed to be read without contacting us:
Every page here prints cleanly to PDF if you need to attach one to a review file.
If you have a security questionnaire, send it to aiome.io/contact. We will complete it honestly, including the questions where the answer is "not yet."
Related documents: Data Processing Addendum · Subprocessors · Privacy Policy · Acceptable Use Policy