Skip to content
Aeologic AI

Legal

Security

Last updated 12 August 2026

This page summarises our security posture. Enterprise customers receive the full security package — SOC 2 report, penetration test summary, sub-processor list and DPA — under NDA during procurement.

1. Certifications and audits

SOC 2 Type II, audited annually by an independent firm. The current report is available under NDA.

Independent penetration testing twice a year against the application and infrastructure, with an executive summary shared on request.

GDPR and UK GDPR compliant, with a Data Processing Agreement available for all customers and Standard Contractual Clauses for international transfers.

2. Encryption and infrastructure

TLS 1.3 for all data in transit. AES-256 for data at rest, including backups.

Infrastructure runs in hardened cloud environments with network segmentation, private subnets for data stores, and no direct public access to databases.

Secrets are managed in a dedicated key management service with automatic rotation. No credentials are stored in source control.

3. Access control

Production access requires SSO with hardware-backed multi-factor authentication, is granted on a least-privilege basis, is time-bound and is fully logged.

Customer accounts support SAML 2.0 SSO and SCIM provisioning on Enterprise plans, with role-based permissions down to the field level.

Access reviews are conducted quarterly and on every role change or departure.

4. AI model handling

Where the platform calls a third-party model, we use enterprise endpoints configured with training disabled and zero data retention where the provider offers it.

Customer content is never used to train third-party foundation models, and never used to improve models for other customers.

Enterprise customers can restrict which model providers may be used for their workspace.

5. Availability and continuity

Multi-zone deployment with automated failover. Encrypted backups taken continuously with point-in-time recovery.

Recovery objectives: RPO under 5 minutes, RTO under 4 hours. Restore procedures are tested quarterly.

A 99.9% uptime SLA applies to Enterprise plans with a signed agreement.

6. Vulnerability disclosure

If you believe you have found a vulnerability, email security@aeologic.ai with enough detail to reproduce it. We acknowledge within one business day.

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us reasonable time to remediate before disclosure.

We do not currently run a paid bounty programme, but we credit researchers publicly with their consent.

7. Incident response

We maintain a documented incident response plan with defined severities, on-call rotation and post-incident review.

Affected customers are notified of a personal data breach without undue delay, and within 72 hours where legally required.

Post-incident reviews for customer-affecting incidents are published to affected customers within ten business days.

This document is provided as part of a demonstration website and is not legal advice. Before using it on a live commercial service, have it reviewed by qualified counsel in every jurisdiction where you operate.