Aimable Trust Center
Security is the foundation of everything Aimable builds. This page is about the Aimable Platform: first how your data is protected while people and agents are actually working with it, then the certifications, controls, subprocessors and policies of the company that builds and runs it.
How we handle personal data on aimable.ai, the website you are reading now, is a separate matter, set out in our privacy statement.
How the platform protects your data.
Six things the platform does on every question, for your people and for your agents alike. They are set once and applied automatically, so nobody has to remember them.
You choose where the AI runs
How that worksA Space can be set to an open-source AI on dedicated EU GPUs, or on your own hardware, so the work never reaches a company that builds AI.
Your rules, per team
How that worksWhich AI, which sources, which tools, who sees what: set per Space, applied automatically, refused when unclear.
Grounded, with the source
How that worksEvery answer cites its sources, and every citation is a link. One click opens the document it was based on, so anyone can check it.
A log of everything
How that worksWho asked what, which sources were used, what it cost. For your auditor, and for you.
Hosted in the EU, in our cloud or yours
How that worksThe platform runs in our EU cloud, or in your own cloud if you prefer. That choice is yours to make, whatever your size.
Never locked in
How that worksAny AI, switchable per Space. Escrow on the code on request. Your data and your knowledge stay yours.
For the most sensitive data, you choose where the AI runs.
Open-source AI has become good enough that running it on infrastructure you can name is often the better answer rather than the compromise. A Space that handles your most sensitive material can be set to an open-source AI, and the work then never reaches a company that builds AI.
That is the distinction that matters, and it sits in how the arrangement is put together rather than in anyone's assurance. A company whose business is building AI has a reason to want training data. A company whose business is renting out GPUs in Europe has no AI of its own to improve, so your documents are of no use to it.
Where that AI runs is your choice. By default it runs on dedicated GPUs inside the EU, through TensorX in Ireland, which is named in our subprocessor list below. If you have your own hardware, it runs there instead and the material never leaves your own infrastructure at all.
Each Space allows the AI you choose, and they can differ. The team working on public material can use the strongest hosted AI available; the team handling personnel files or client records can be pinned to an open-source one. Same platform, same rules, same log, a different answer to where the data is allowed to go.
Your rules, set per team and applied on every question.
A Space is the work area of one team. Its policies set what may and may not happen there: which AI the team may use, how personal data is handled, which tools and skills it may use, and who sees what. Set once, applied on every question, for your people and your agents alike. Every connection into a Space is read-only unless you decide otherwise, and is scoped to that Space.
Every answer checkable, at the source.
Answers draw on your own curated collections of documents and data, and each one cites where it came from. Click the citation and the document opens at the passage, so a check takes seconds. We do not ask anyone to take an answer on trust: the point is that it can be verified in a few seconds by the person who has to sign off on it.
A logbook of what happened, and what it cost.
The Console shows who asked what, which sources were used, which AI answered and what it cost, per team and as it happens. A budget per Space or for the whole company is a hard cap, with alerts at the thresholds you set. The same record serves two purposes: it answers your auditor, and it tells you where AI is actually paying back.
Redaction, for where it is the right tool.
Where a hosted AI is the right choice for the work, the Redaction module finds names, email addresses, ID numbers and other personal data and replaces them before the request leaves, then puts them back in the answer your people read. It works on text, files and images, in every language your team works in.
It is one tool among several, not the answer to every sensitive case. When data is sensitive enough that it should not reach a company that builds AI at all, an open-source AI is the better route, and the platform offers both. The Privacy Check is the part your people see: before a message goes out it shows what it found, so they learn what counts as personal data at the moment it matters.
Where it runs, and what stays yours.
The platform runs in our EU cloud, on European infrastructure. You can also choose to run it inside your own cloud, whatever the size of your company, and where the work should not reach a company that builds AI, an open-source AI runs instead, on dedicated EU GPUs or on your own hardware.
Each Space allows the AI you choose. A change at one provider does not put your work at risk, because the same skills run on another AI without rebuilding, and your accumulated knowledge never lives inside one vendor. Escrow on the code is available on request. Your data and your collections stay yours, and leave with you.
Compliance.
GDPR
Compliant
EU AI Act
Ready
SOC 2 Type II
In progress. In active certification; the latest audit status is available on request.
ISO/IEC 27001:2022
Certified
81 security controls across 22 categories
Our security programme covers 81 controls across 22 categories, independently verified and continuously monitored.
- Asset management, 2 controls
- Business continuity and disaster recovery, 2 controls
- Compliance, 1 control
- Configuration management, 1 control
- Continuous monitoring, 1 control
- Cryptographic protections, 3 controls
- Cybersecurity and data privacy governance, 4 controls
- Data classification and handling, 2 controls
- Data privacy, 30 controls
- Endpoint security, 2 controls
- Human resources security, 5 controls
- Identification and authentication, 6 controls
- Incident response, 3 controls
- Mobile device management, 1 control
- Network security, 2 controls
- Risk management, 2 controls
- Secure engineering and architecture, 5 controls
- Security awareness and training, 1 control
- Security operations, 1 control
- Third-party management, 4 controls
- Vulnerability and patch management, 2 controls
- Web security, 1 control
Subprocessors for the platform.
Where your data goes when the platform runs. These three are the only parties that touch what your teams put into their Spaces, and all three are European.
Scaleway
Cloud infrastructure, France
Hetzner
Cloud infrastructure, Germany
TensorX
AI inference on dedicated GPUs, Ireland
Subprocessors for running our company.
The tools we run the company on. They hold our correspondence and our record of who our customers are. They are not part of the platform, and the content of your Spaces does not pass through them.
Google Workspace
Mail, documents and calendars, United States
Slack
Internal messaging, United States
Attio
Customer records, United Kingdom
Linear
Product and issue tracking, United States
Policies and resources.
Our policies are available on request. Mail the CISO and name the document you need.
Questions about security?
Our team can walk you through our security practices, compliance certifications, and deployment options.
Shall we walk through it together?