Security and data/Compliance and accessibility

Certifications held are listed here. Certifications in progress are listed only once begun.

This table is written to be relied on. Nothing here is aspirational. Where AIMIS does not hold something, the page says so and says what is available instead.

Request the security overviewTrust center
No third party certifications held today · documentation on request
Compliance posture

Where AIMIS stands today.

Framework by framework. A status, what it means for an evaluation, and the next step where there is one.

FrameworkStatus todayWhat that means for an evaluationNext step
SOC 2 Type IINot heldSecurity documentation is available on request in place of a reportConfirm roadmap
FedRAMPNot heldAIMIS is not a FedRAMP authorized service. Agencies evaluate under their own risk processConfirm position
NIST SP 800-171No attestationA control by control statement can be produced on request ConfirmOn request
Section 508 / WCAG 2.1 AAConfirm statusAccessibility conformance report for the app and this siteOn request
CJISNot applicableAIMIS does not process criminal justice information
ITAR / EARNot supportedNot built for classified, controlled or restricted environments
HIPAANot applicableAIMIS does not process protected health information
State and local requirementsCase by caseReviewed against each engagement's requirementsScoping conversation
Policies

Public where they can be, on request where they must be.

Accessibility statementThis site and the app.

Commitment to WCAG 2.1 AA, known limitations listed plainly, and a contact for accessibility issues. Conformance report on request. Confirm status

On request →
Vulnerability disclosureHow to report, what to expect.

A public address for reports, acknowledgement within Confirm business days, safe harbor for good faith research, and no bounty program today.

On request →
Incident responseWhat happens if something goes wrong.

Detection, containment, customer notification within Confirm hours of confirmation, and a written summary after. Full plan on request.

On request →
Business continuityBackups and recovery.

Recovery objectives, backup frequency and retention. Confirm Full summary on request.

On request →
Why the page reads this way

A reviewer should be able to rely on every sentence.

Most vendor compliance pages are written to pass a glance. This one is written to survive a read.

Where AIMIS does not hold something, the page says so and says what is available instead. Where a requirement is specific to an engagement, it is handled in the engagement plan, not implied here.

Ask for the control statement.

Produced on request for organizations in an active evaluation.

Request the security overview