Security
Security as architecture,
not afterthought
Our security model is designed from first principles for sovereign deployment, where data never leaves the customer's jurisdiction and auditability is a hard requirement, not a nice-to-have.
Infrastructure
Core security properties
Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. For on-premise deployments, encryption keys never leave the customer's infrastructure. We do not hold master keys for sovereign deployments, by design.
Access Control
Role-based access control (RBAC) with zero-trust network architecture. Every service-to-service call is authenticated. Privileged access requires hardware security key MFA and is time-limited. Access logs are immutable and independently auditable.
Audit Trails
Comprehensive, tamper-evident audit logging across all API calls, model invocations, and administrative actions. Logs are cryptographically signed and can be forwarded to customer-controlled SIEM infrastructure. Retention period is configurable per compliance requirement.
Vulnerability Management
Continuous automated vulnerability scanning, quarterly penetration tests by independent security firms, and a public bug bounty programme. Critical vulnerabilities are patched within 24 hours. Security advisories are published to affected customers before public disclosure.
Infrastructure
How we secure our systems
Our cloud infrastructure uses a hardened baseline configuration derived from CIS benchmarks, with infrastructure-as-code to ensure every environment is reproducible and deviation-detectable. Network segmentation ensures that training infrastructure, inference infrastructure, and customer-facing APIs are fully isolated with explicit allow-listed traffic paths only.
For on-premise and sovereign deployments via the Federated Mesh, the security model is extended to support air-gapped operation. In air-gapped mode, the system operates without any outbound network connections. Model updates are delivered through a signed, verified update mechanism that can be reviewed before application.
Compliance
Certifications & standards
SOC 2 Type II
Our SOC 2 Type II audit is underway, covering security, availability, and confidentiality trust service criteria. Expected completion Q3 2026. Customer NDA-bound audit reports available on request during the interim period.
ISO 27001
We are implementing an ISO 27001-aligned Information Security Management System (ISMS) with target certification in 2027. Our security controls are already mapped to the ISO 27001 Annex A control set.
Data Protection
AICONSORTIUM's data processing practices are built to comply with modern data-protection law worldwide, including the GDPR, the DPDPA, and equivalent frameworks aligned principles for the jurisdictions we serve. We have appointed a Data Protection Officer and maintain a Data Processing Register available to regulators on request.
Disclosure
Vulnerability disclosure & bug bounty
We operate a responsible disclosure programme for security researchers who identify vulnerabilities in our systems. We commit to acknowledging reports within 48 hours, providing a triage decision within 7 days, and issuing a fix for confirmed critical vulnerabilities within 30 days.
Our bug bounty programme rewards researchers who responsibly disclose vulnerabilities with monetary bounties scaled to severity. Critical infrastructure vulnerabilities may qualify for bounties up to USD 6,000 (or local-currency equivalent). We do not pursue legal action against researchers who act in good faith under our disclosure policy.