Aixy·
GDPR EU AI Act Security Subprocessors Privacy

Security & privacy

Technical and organizational measures

The safeguards Aixy uses to protect account, operational and customer-controlled personal data.

Last reviewed
26 August 2026
Status
Publication draft
Not a public compliance claim yet.

This material is prepared for review, but Aixy has not enabled the GDPR compliance claim. The remaining evidence and approval gates are listed on the GDPR transparency page.

Access and tenant isolation

  • Organization- and project-scoped authorization with granular permissions.
  • Project API keys are returned once; only cryptographic hashes and lifecycle metadata are retained.
  • Provider credentials are write-only and encrypted with a versioned AES-256-GCM key ring.
  • Browser sessions use host-only, HttpOnly, SameSite=Lax cookies and Secure on HTTPS.
  • Passwords are hashed with Argon2id; passkeys store public credential material, not private keys or biometric data.

Data minimization and content handling

  • Prompts and responses are excluded from application logs, metrics, traces, analytics, audit events and telemetry exports by default.
  • Optional content capture requires an explicit organization or project policy and a separate content-read permission.
  • Captured prompt or response values are bounded to 150,000 bytes per side and encrypted before asynchronous storage.
  • Content is retrieved only through an explicit, tenant-authorized detail request and is removed from live storage after the selected retention period.
  • Operational telemetry uses bounded fields and plan-specific physical retention.

Infrastructure and encryption

  • Primary regional infrastructure is deployed in AWS eu-central-1 (Frankfurt).
  • PostgreSQL storage, S3 archives and Kinesis transport are encrypted at rest; TLS protects network traffic.
  • Production databases and telemetry services are private and accessed administratively through authenticated AWS Systems Manager sessions.
  • Secrets are kept in a deployment secret manager and are not committed to source control or exposed to browser code.
  • Cloud service access logs and infrastructure audit records have configured retention windows.

Monitoring, evidence and resilience

  • Tenant audit events record bounded actor, access, configuration and security evidence without copying model content or secrets.
  • Operational analytics are separated from the model-forwarding hot path and remain tenant scoped.
  • Encrypted backups, versioned infrastructure, deployment rollback and health alarms support recovery.
  • Organization deletion uses a recoverable period followed by an owner-credential purge gate, scoped retention holds, exact confirmation, and a hashed deletion receipt.
  • Incident procedures include triage, evidence preservation, risk assessment, customer notification and regulatory escalation.

Customer responsibilities

Customers configure users, projects, provider credentials, models, retention, content capture and downstream destinations. They remain responsible for lawful instructions, notices, data minimization, access reviews and selecting model providers appropriate to their use case.

Assurance status

These measures describe implemented product and infrastructure controls. They are not an ISO 27001, SOC 2 or Article 42 GDPR certification. Additional evidence can be shared with qualified enterprise prospects under appropriate confidentiality terms.

Aixy·
Privacy Cookies Legal notice DPA EU AI Act Compliance contact