Trust & data protection

Your data stays in your region. And yours.

Pick EU or US once at signup. Roles are enforced in the database, every tenant is isolated, and you can export everything anytime. Here's the posture, in plain terms.

Data residency

EU or US - your choice, enforced at ingest

You pick your region once at signup, based on where your company is. It is invisible afterward - never in a URL, a key, or the UI - and enforced where data enters the system.

  • ✓Chosen once, applied everywhere
  • ✓Included on every plan from $199/mo
  • ✓Enterprise adds contractual region pinning

Isolation & access

Roles enforced in the database, not the UI

AIOProductOS is multi-tenant from the first row. Every record carries an organization ID, and row-level security scopes access to it. Permissions are checked in the database - hiding a button is never the control.

  • ✓Per-tenant row-level security
  • ✓Roles and permissions enforced server-side
  • ✓Cross-tenant reads require service access, audited

Your data is portable

Export everything, anytime, on every tier

An owner or admin can export the whole organization as JSON and CSV whenever they want. Most tools gate full export to Enterprise - we don't. Import is one-way, so your other tools are never written to.

  • ✓Full-org JSON + CSV export
  • ✓Not gated to Enterprise
  • ✓One-way import - read-only on the source

Privacy-first capture

First-party SDKs that respect opt-outs

The SDKs set no cookies - identity is a first-party id in local storage, never shared across sites or sold - and they honour Do Not Track and Global Privacy Control out of the box. One opt-out call silences every SDK at once and deletes that id, so consent is one switch, not a vendor-by-vendor chase.

  • ✓No cookies, no cross-site tracking
  • ✓DNT and GPC honoured
  • ✓One opt-out silences everything

Encryption & compliance

Encrypted at rest, never used to train AI, and run as a live compliance program.

Connector secrets are sealed with BYOK envelope encryption - a per-organization key, AES-256-GCM - and data at rest is AES-256 encrypted. We never train AI models on your data. Compliance runs as a live program: over 150 security and privacy controls mapped across 18 frameworks, including SOC 2, ISO 27001, GDPR and HIPAA. That is readiness we show, not a certification we claim, until an external audit completes.

  • ✓BYOK envelope encryption - per-org key, AES-256-GCM
  • ✓No AI model ever trains on your data
  • ✓150+ controls across 18 frameworks - readiness, not certification

Live compliance dashboard ↗ How we handle AI & your data → Report a vulnerability →

Answer integrity

The numbers are tested, not trusted

When the spine answers 'which features have the most MRR behind them?', that number is computed from your data - no LLM guessing. A 200-case eval proves it stays correct: grounding (the right answer on real data) plus adversarial math invariants (sums match the headline, percentages total 100, rankings hold, no fabricated totals). It runs in CI on every change to the answer engine.

202/202

100% passing

50 of them adversarial

  • Grounding

    50

    Every spine question returns a real, data-backed answer on a live org - the right headline, the right top row, the right counts.

  • Adversarial math invariants

    50

    The checks a string test misses: row values must sum to the headline, percentages must total 100, 'top' rows must actually be sorted, no fabricated totals.

  • Shape & edge

    102

    Every answer is well-formed in every branch - a non-blank headline, a substantive detail line, bounded rows - grounded or honestly empty, never a crash.

Last verified by a live run on 2026-06-25 · the eval is part of the product, not a marketing claim - it gates every change to the answer engine.

Billing & uptime

Payments processed securely by Stripe

Subscriptions are sold by AIOProductOS Inc. and processed by Stripe. Card data never touches our servers; VAT or sales tax is added at checkout where applicable.

  • Stripe payment processing

    Card handling is Stripe's (PCI DSS SAQ-A) - we never store payment details.

  • Public status page

    Runs on separate infrastructure, so it stays up even if we don't.

Who you're buying from

The company behind the product

AIOProductOS is operated by AIOProductOS Inc. (a Delaware C-Corporation, United States). For a DPA or BAA, region pinning, or your specific compliance and subprocessor questions, email office@aioproductos.com and we'll share the current posture.

Related: Privacy · Terms · Refund policy

FAQ

Questions, answered

How does AIOProductOS handle security and data?

Your data lives in the region you choose at signup - EU or US - enforced at ingest. Every record is scoped to your organization by row-level security in the database, so one tenant can never read another's, and roles are enforced server-side, not hidden in the UI. Connector secrets are sealed with BYOK envelope encryption (a per-organization key, AES-256-GCM), data at rest is AES-256 encrypted, and we never train AI models on your data. An owner or admin can export the whole organization as JSON and CSV anytime, on every tier. Compliance runs as a live program - over 150 controls mapped across 18 frameworks including SOC 2, ISO 27001, GDPR and HIPAA - readiness we track on a public dashboard, not a certification we claim, until an external audit completes. Payments are processed by Stripe (PCI DSS SAQ-A), and Enterprise adds a contractual DPA or BAA with region pinning.

Where is my data stored?

In the region you pick at signup - EU or US. The choice is enforced at ingest, so your records live and stay on that region's infrastructure.

How is one company's data kept separate from another's?

Every record carries an organization ID, and row-level security in the database scopes reads and writes to that organization. Roles are enforced in the database, not just hidden in the UI.

Can I get my data out?

Yes, anytime, on every tier. An owner or admin can export the whole organization as JSON and CSV. Import is one-way, so nothing is written back to your other tools.

Do you have a DPA, and which compliance certifications?

Enterprise plans add a contractual DPA or BAA and region pinning. For your specific compliance and subprocessor questions, email office@aioproductos.com and we'll share the current posture.

Get started

Run it on your real data - in your region.

Create a workspace, pick EU or US, and your data stays there. Need a DPA first? We'll send one.