Security and data/Architecture and deployment

A phone, an encrypted connection, a cloud application.

How AIMIS is built and deployed, at the level a reviewer needs before an architecture conversation. Nothing on this page is proprietary. The detailed diagram is available on request.

Request the security overviewTrust center
Cloud application · Vendidit operated · Amazon Web Services
Data flow

From the photograph to the export.

01
PhoneCapture device · iOS / Android
02
Encrypted transportTLS in transit
03
AIMIS cloud on AWSVendidit operated · region Confirm
04
Identification serviceCommercial AI · provider agnostic
05
ExportCSV / Excel to the customer
What leaves the device

Photographs and the item data built from them. Location metadata is optional and configurable.

What is stored

Records and photographs, until the customer deletes them. Storage details: Confirm encryption at rest, backups

What leaves the cloud

Only the export the customer takes, and photographs sent to the identification service for processing.

Deployment models

What is offered today, and what is not.

Each model is stated with its status. Where something is not offered, the page says so and says why.

ModelDescriptionStatus
Standard cloudMulti tenant application operated by Vendidit on AWS. The default for walkthroughs, pilots and production.Available
Dedicated tenantA separate account or region for one organization, with the same application.On requestConfirm
Isolated or on premisesA copy running inside a customer environment with no outbound calls. Identification depends on a hosted service today, so this is not offered.Not offered today
Restricted areasWhere camera or device use is restricted, capture happens where policy allows, during packing or staging outside the area. Scoped per facility.Scoping conversation
Controls

The short list a reviewer asks about first.

Items still to be confirmed are marked. Nothing marked ships.

ControlTodayDetail
Encryption in transitTLS for every connection from the phone and the browserConfirm TLS version
Encryption at restConfirmConfirm key management
Tenant separationConfirm logical separation modelDedicated tenant on request
Access controlRole based, administered by the customer Confirm rolesCustodian, reviewer, administrator Confirm
Audit eventsConfirm what is logged and retention
Backups and recoveryConfirm frequency, retention, recovery objectives
MonitoringConfirm
Identification serviceCommercial AI, currently OpenAI. Provider agnostic.Customer data not used for training: Confirm contract terms · Subprocessor list

Request the architecture diagram.

Provided under non disclosure agreement to organizations in an active evaluation.

Request the security overview