Security at AIGiner
Here's how we protect what you entrust to us: defence in depth, least privilege and everything inside the European Union.
No single measure works alone
Every layer assumes the one before it can fail. This is how we protect your data from the edge to the database.
Edge and WAF
Cloudflare with an active WAF, rules against known scanners and Bot Fight Mode in front of every request that comes in.
Encryption in transit and at rest
HTTPS enforced with HSTS and TLS 1.2+. Sensitive data is encrypted in the database, with the key kept outside the repository.
Per-client isolation
Multi-tenant PostgreSQL with Row-Level Security: every query is restricted to your account's rows, even if the application had a logic bug.
Access control
Two-factor authentication on every administrative account, and access to the production server only via SSH key, never a password.
Backups
Daily backups following the 3-2-1 rule (three copies, two media, one off-site) and a monthly restore drill.
Monitoring
Continuous system monitoring with automatic escalation if something degrades, before you notice it.
The rules we don't negotiate
Least privilege
Every person and every system only accesses what it needs to do its job, nothing more.
Data inside the European Union
All our infrastructure lives on European soil. Nothing is replicated outside it without your explicit written consent.
GDPR by design
Compliance isn't bolted on at the end of a project: it's designed in from day one, for every client.
No system is unhackable
Anyone who tells you otherwise is selling you something. Our commitment isn't perfection: it's applying everything we've got to keep things as secure as we possibly can, being honest about what we still lack, and responding fast when something breaks.
Have a specific security question?
Write to us at security@aiginer.com. We answer procurement questionnaires and internal audits without asking for a contract first.