Skip to content
Security

Security at AIGiner

Here's how we protect what you entrust to us: defence in depth, least privilege and everything inside the European Union.

Defence in depth

No single measure works alone

Edge and WAF

Cloudflare with an active WAF, rules against known scanners and Bot Fight Mode in front of every request that comes in.

Encryption in transit and at rest

HTTPS enforced with HSTS and TLS 1.2+. Sensitive data is encrypted in the database, with the key kept outside the repository.

Per-client isolation

Multi-tenant PostgreSQL with Row-Level Security: every query is restricted to your account's rows, even if the application had a logic bug.

Access control

Two-factor authentication on every administrative account, and access to the production server only via SSH key, never a password.

Backups

Daily backups following the 3-2-1 rule (three copies, two media, one off-site) and a monthly restore drill.

Monitoring

Continuous system monitoring with automatic escalation if something degrades, before you notice it.

Principles

The rules we don't negotiate

Least privilege

Every person and every system only accesses what it needs to do its job, nothing more.

Data inside the European Union

All our infrastructure lives on European soil. Nothing is replicated outside it without your explicit written consent.

GDPR by design

Compliance isn't bolted on at the end of a project: it's designed in from day one, for every client.

With honesty

No system is unhackable

Anyone who tells you otherwise is selling you something. Our commitment isn't perfection: it's applying everything we've got to keep things as secure as we possibly can, being honest about what we still lack, and responding fast when something breaks.

Have a specific security question?

Write to us at security@aiginer.com. We answer procurement questionnaires and internal audits without asking for a contract first.