In plain English
An automation platform holds a lot of power over your estate, so we designed it to hold as little as possible: no standing credentials, hard blast-radius limits, and an audit trail we cannot alter. Report anything you find to security@aiinfraengine.com.
1. Certifications and audits
- SOC 2 Type II — audited annually across security, availability and confidentiality. Report available under NDA.
- ISO 27001 — certified information security management system covering all operations.
- Annual third-party penetration test — executive summary available to customers.
- Continuous automated vulnerability scanning of infrastructure, dependencies and container images.
2. Credential handling
The platform holds no standing credentials for your environment. Secrets are brokered per execution from your own vault — HashiCorp Vault, Azure Key Vault or CyberArk — injected into an ephemeral runner, and destroyed with it.
Where an integration requires a stored credential, it is encrypted with a per-tenant key in a hardware security module, and every retrieval is an auditable event.
3. Execution safety
- Blast-radius ceilings — every automation declares the maximum scope it may touch, enforced by the engine rather than by convention.
- Ephemeral runners — each execution runs in a fresh container with a hard timeout and no network access beyond its declared targets.
- Approval gates — configurable per automation, with delegation, timeout and break-glass paths that require justification.
- Reversibility — actions carry compensating operations; rollback is a first-class execution with its own audit record.
- Kill switch — one command halts all unattended execution tenant-wide. We recommend testing it monthly.
4. Data protection
- TLS 1.3 in transit; AES-256 at rest with per-tenant keys.
- Customer content is logically isolated with row-level security enforced at the database, not in application code.
- Data residency is contractual — US, EU, UK or Australia, and it does not move without your instruction.
- Backups are encrypted, tested quarterly by restore, and retained per your configured policy.
5. Access control
Staff access to production requires hardware MFA, is granted just-in-time for a specific task, is fully session-recorded, and expires automatically. No engineer holds standing production access.
Access to customer environments during support requires your explicit, time-bound, per-session consent, granted from your support portal and revocable at any moment.
6. Reporting a vulnerability
Email security@aiinfraengine.com with reproduction steps. Our PGP key is published at aiinfraengine.com/.well-known/security.txt.
We acknowledge within 24 hours, provide an assessment within 5 business days, and keep you updated until resolution. We will credit you publicly unless you prefer otherwise.
We do not pursue legal action against good-faith researchers who test only against their own tenancy, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosure.
7. Incident response
We maintain a documented incident response plan, exercised twice yearly. Customers affected by a security incident are notified without undue delay and within 72 hours of confirmation, with a factual account of what happened, what data was involved and what we are doing about it.
Post-incident reviews are shared with affected customers, including the parts that reflect badly on us.
Questions about this?
Write to legal@aiinfraengine.com, or our Data Protection Officer at dpo@aiinfraengine.com. Postal enquiries: AIInfraEngine, Herengracht 182, 1016 BR Amsterdam, Netherlands.