Trust center

AIDA is built for teams that take data security seriously. This page summarizes how we handle your data, our security controls, and our ongoing compliance posture.

Where your data lives

How we encrypt your data

Authentication

Audit + observability

Every authenticated API request is recorded with timestamp, tenant, user (or API key), method, path, status, and IP. Audit retention: 90 days hot + 1 year cold. Application logs retained 30 days.

Backups + disaster recovery

Nightly logical Postgres backups, retained 30 days. Quarterly restore drill against a scratch environment. RPO: 24 hours. RTO: 1 hour.

Sub-processors

VendorPurposeAttestation
AnthropicLLM (agent answers)SOC 2 Type II
OpenAIEmbeddingsSOC 2 Type II
HetznerHostingISO 27001
GitHubSource control + PR-on-editSOC 2 Type II

Compliance

Contact

For security issues, write to security@<DOMAIN>.

Last updated: 2026-05-14.