Sovereign footprint
AION runs inside your cloud, VPC, on-prem or air-gapped gateway. It prices and routes traffic locally, never exporting prompts, responses or evidence.
- In-boundary data routing
- No prompt or response export
- Customer-side evidence
We’re early. We don’t claim certifications we don’t have. Below is exactly what we do today, what we don’t, and how to talk to us if you find a problem.
Security posture
AION runs inside your cloud, VPC, on-prem or air-gapped gateway. It prices and routes traffic locally, never exporting prompts, responses or evidence.
TLS 1.3 in transit and AES-256 at rest (RDS, EBS, S3). row-level org_id validation prevents cross-tenant data access at query layer.
GDPR Article 17 hard-delete purges data on request. Replay-hashed receipts verify billed events, with a 30-day dispute window.
Compliance transparency
Not yet. We will pursue Type I when the product matures past the design-partner stage. We won’t list it until we have a signed audit report.
Not in scope. We do not process Protected Health Information (PHI) under AION today.
Not in scope. We do not host federal workloads or maintain public sector certifications today.
Customer data is retained according to these standard schedules:
Disclose vulnerabilities to [email protected]. We respond within 5 business days. No bounty program exists today; we will credit you in our security log if you wish.
Infivector-hosted portal, billing and marketing data is stored in AWS us-east-1. We do not replicate to other regions. AION runtime data (prompts, responses and evidence) stays inside your boundary and never reaches our infrastructure. If your workload requires local region hosting, contact us before contracting.