Security at Aimdoc

Built to pass your security review

Aimdoc sits on your website and inside your product. We treat that responsibility accordingly: SOC 2 Type II certified, GDPR compliance in practice, and transparent about our controls.

SOC 2

Type II certified

GDPR

DPA and data subject rights

TLS 1.2+

Encryption in transit and at rest

Trust Center

Policies, reports, and FAQs

Program overview

Organizational, technical, and operational controls

Our security program is aligned to SOC 2 and GDPR, and we continuously improve our controls as we scale.

People

Security training and background checks for employees.

Access control

Least-privilege access and role-based authorization.

Change management

Peer review and change management for production changes.

Vulnerability management

Continuous vulnerability management and regular dependency updates.

Continuity and response

Business continuity and incident response procedures.

Data protection

How we handle your data

Encryption everywhere

TLS 1.2+ in transit, modern ciphers at rest.

Isolated infrastructure

Segregated production environment and secure secrets management.

Backups you can trust

Retention policies and regular restore testing.

Audit logging

Monitoring and audit logs on critical systems.

Your data, your call

Data minimization by default and customer data deletion upon request.

Compliance, documented

We maintain SOC 2 Type II certification and support GDPR compliance, including data processing agreements, data subject access requests, and international transfer mechanisms where applicable. Policies, reports, and FAQs are available in our Trust Center.