Loading
Loading
You are trusting us with your customer conversations. Here is how we protect them, described plainly rather than in marketing terms.
All traffic between you, your customers and AiBA travels over TLS. The site and application are served over HTTPS only.
Data at rest — conversations, contact records and uploaded files — is encrypted on the storage layer.
Access to production systems is restricted to the small number of people who need it to operate the service, and is granted individually rather than through shared logins.
We follow the principle of least privilege: staff get the narrowest access that lets them do their job, and access is revoked when someone changes role or leaves.
We do not read your customer conversations except where you ask us to for support, or where we are legally compelled to.
We host on established cloud providers with their own physical security, redundancy and compliance programmes, rather than running our own hardware.
Our public website is served as static files from a global CDN, which removes an entire class of server-side vulnerability from the part of our estate that faces the open internet.
Each customer's data is logically separated. One customer cannot see another's conversations, contacts or settings.
We keep data for as long as your account is active, and delete it on request under our Data Deletion Instructions. Backups are retained on a rolling basis and age out within 30 days.
Security is shared. Use a strong, unique password, keep it to yourself, and remove access for staff who leave your business.
Be careful about what you put into the system: do not upload payment card numbers, government identity numbers or health records unless we have expressly agreed arrangements for that data.
If we discover a breach affecting your data, we will investigate immediately, contain it, and notify you without undue delay — along with the regulator where the law requires it.
We will tell you what happened, what data was involved, and what we are doing about it. We would rather give you an uncomfortable, accurate account than a reassuring, vague one.
If you believe you have found a security vulnerability, please email aiba.assistantt@gmail.com with the subject line "Security" and enough detail to reproduce it.
Please report it to us privately first and give us reasonable time to fix it before disclosing publicly. We will acknowledge your report, keep you updated, and we will not pursue legal action against researchers who act in good faith and avoid harming customer data.
We are an early-stage business and do not currently hold formal certifications such as ISO 27001 or SOC 2. We have described above what we actually do, rather than implying accreditation we have not earned.
If your procurement process requires specific assurances, contact us and we will answer directly about what we can and cannot commit to today.