Security and data/Trust center

Security and data handling, stated plainly.

What leaves the device. Who processes it. What is kept, and who controls it. This page states what AIMIS does today. Detailed documentation is available to organizations in an active evaluation.

Request the security overview Report a vulnerability
Deployment · today · cloud application on AWS
03 · Cloud
AWSOperated by Vendidit. Dedicated tenant on request.
02 · In transit
TLSEncrypted connections from the phone and the browser.
01 · Phone
Capture deviceiOS or Android. Nothing stored beyond capture.
Principle

We state what we hold, and nothing we do not.

AIMIS works with each organization and its partners on the requirements of the engagement. Where a requirement is not yet met, this page says so and the engagement plan says how.

That posture is deliberate. An organization evaluating the product should be able to rely on every sentence here. Items marked Confirm are facts still to be supplied before this page goes live. Nothing marked ships.

Five areas

Each stated plainly, each with its own page.

AreaWhat is true todayDetail
01Hosting and infrastructure

Records are processed on Vendidit operated infrastructure hosted on Amazon Web Services. Regions: Confirm

Architecture and deployment
02Deployment models

A cloud application operated by Vendidit. The phone is the capture device. Dedicated tenancy on request Confirm. Isolated or on premises deployment is not offered today.

Architecture and deployment
03Data in transit and at rest

Photographs and item data are transmitted over encrypted connections (TLS in transit). At rest: Confirm encryption and key management

Data handling and retention
04Access and administration

Role based access administered by the customer Confirm roles. Audit events: Confirm

Data handling and retention
05Compliance posture

No third party certifications are held today. Security documentation is available on request. Certifications in progress are listed only once begun.

Compliance and accessibility
Document library

What a reviewer can ask for.

Public documents are linked. Everything else is provided under non disclosure agreement to organizations in an active evaluation.

DocumentWhat it coversAvailability
Security overviewHosting, separation, data handling, access, incident handling in plain languageOn request
Architecture diagramPhone, transport, processing, storage, exportOn request
Data flow and retention summaryWhat is collected, where it goes, how long it stays, who can delete itOn request
Subprocessor listEvery third party that processes customer dataPublic · below
Data processing termsContractual terms on data handlingUnder NDAConfirm
Vulnerability disclosure policyHow to report, what to expect, safe harborPublic
Incident response summaryDetection, notification timelines, customer communication ConfirmOn request
Accessibility conformance reportWCAG 2.1 AA status for the app and this site Confirm statusOn request
Business continuity summaryBackups, recovery objectives ConfirmOn request
Subprocessors

Every third party that touches customer data.

The list is public and kept current. The identification architecture is provider agnostic, so the service can be changed without changing the product.

ProviderPurposeData involvedLocation
Amazon Web ServicesHosting and storage of the application and recordsPhotographs, item data, account dataConfirm region
OpenAICurrent provider
Item identification and description from photographs. The architecture is provider agnostic and the service can be changed without changing the product.Photographs and derived item dataUnited StatesConfirm
HubSpotWebsite forms and inquiry routingContact details submitted on this siteUnited States
Confirm othersEmail delivery, monitoring, support toolingConfirmConfirm
Security inquiriessecurity@Domain

For reviewers and assessors. Response within Confirm business days.

Write to security →
Vulnerability reportsReport a vulnerability

Public disclosure policy with safe harbor. Acknowledgement within Confirm business days.

Read the policy →
Data requestsDeletion and export

Deletion is in the customer's control. Location metadata retention is configurable and can be stripped on request.

Data handling and retention →

Request the security overview.

Provided to organizations in an active evaluation, under non disclosure agreement.

Request the security overview