Security

Security as architecture,
not afterthought

Our security model is designed from first principles for sovereign deployment, where data never leaves the customer's jurisdiction and auditability is a hard requirement, not a nice-to-have.

Infrastructure

Core security properties

Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. For on-premise deployments, encryption keys never leave the customer's infrastructure. We do not hold master keys for sovereign deployments, by design.

Access Control

Role-based access control (RBAC) with zero-trust network architecture. Every service-to-service call is authenticated. Privileged access requires hardware security key MFA and is time-limited. Access logs are immutable and independently auditable.

Audit Trails

Comprehensive, tamper-evident audit logging across all API calls, model invocations, and administrative actions. Logs are cryptographically signed and can be forwarded to customer-controlled SIEM infrastructure. Retention period is configurable per compliance requirement.

Vulnerability Management

Continuous automated vulnerability scanning, quarterly penetration tests by independent security firms, and a public bug bounty programme. Critical vulnerabilities are patched within 24 hours. Security advisories are published to affected customers before public disclosure.

Infrastructure

How we secure our systems

Our cloud infrastructure uses a hardened baseline configuration derived from CIS benchmarks, with infrastructure-as-code to ensure every environment is reproducible and deviation-detectable. Network segmentation ensures that training infrastructure, inference infrastructure, and customer-facing APIs are fully isolated with explicit allow-listed traffic paths only.

For on-premise and sovereign deployments via the Federated Mesh, the security model is extended to support air-gapped operation. In air-gapped mode, the system operates without any outbound network connections. Model updates are delivered through a signed, verified update mechanism that can be reviewed before application.

Compliance

Certifications & standards

In Progress

SOC 2 Type II

Our SOC 2 Type II audit is underway, covering security, availability, and confidentiality trust service criteria. Expected completion Q3 2026. Customer NDA-bound audit reports available on request during the interim period.

Target 2027

ISO 27001

We are implementing an ISO 27001-aligned Information Security Management System (ISMS) with target certification in 2027. Our security controls are already mapped to the ISO 27001 Annex A control set.

Compliant

Data Protection

AICONSORTIUM's data processing practices are built to comply with modern data-protection law worldwide, including the GDPR, the DPDPA, and equivalent frameworks aligned principles for the jurisdictions we serve. We have appointed a Data Protection Officer and maintain a Data Processing Register available to regulators on request.

Disclosure

Vulnerability disclosure & bug bounty

We operate a responsible disclosure programme for security researchers who identify vulnerabilities in our systems. We commit to acknowledging reports within 48 hours, providing a triage decision within 7 days, and issuing a fix for confirmed critical vulnerabilities within 30 days.

Our bug bounty programme rewards researchers who responsibly disclose vulnerabilities with monetary bounties scaled to severity. Critical infrastructure vulnerabilities may qualify for bounties up to USD 6,000 (or local-currency equivalent). We do not pursue legal action against researchers who act in good faith under our disclosure policy.

Report a vulnerability Disclosure policy →