Ageiro ARK, the Decision Intelligence Layer for AECO
Security

Security & Trust Center

Your data security is our foundation. Enterprise-grade protection at every layer of the platform.

Certification Status

Built to industry-recognized security standards.

ARK supports SOC 2 Type II and ISO 42001. Our certification program is underway, with independent audit scheduled for September 2026. We publish our status as it stands, not as we would like it to look.

SOC 2 Type II

Infrastructure supporting SOC 2 Type II, with controls mapped to the trust services criteria for availability, confidentiality, and processing integrity. Our audit is scheduled for September 2026.

ISO 42001 Supported

AI management system controls mapped to the ISO 42001 standard for responsible AI governance. Independent audit scheduled for September 2026.

GDPR Compliant

Full compliance with EU General Data Protection Regulation, including data processing agreements.

Zero AI Data Retention

Contractual zero data retention with every AI provider. Your documents and queries are never used to train models.

ICO Registered

Registered with the UK Information Commissioner's Office as a data processor and controller.

Infrastructure

Defense in depth.

AES-256 Encryption at Rest

All stored data is encrypted using AES-256, including documents, embeddings, metadata, and audit logs.

TLS 1.3 in Transit

All data in transit is protected with TLS 1.3. Certificate pinning is available for enterprise deployments.

Multi-Factor Authentication

MFA enforcement across all user accounts, with support for hardware security keys (FIDO2).

SSO Integration

SAML 2.0 and OIDC single sign-on with your existing identity provider: Azure AD, Okta, Google Workspace.

Role-Based Access Control

Granular RBAC ensuring users only access data they are authorized to see. Inherited from your identity provider.

Complete Audit Trails

Every query, response, and data access event is logged with timestamps, user identity, and source references.

AI Data Handling

Zero data retention with AI providers.

ARK enforces strict data handling policies with all AI providers. Your documents and queries are never stored by third-party AI services and are never used to train models. Every response is grounded in your data, with full provenance.

  • Zero data retention: queries are ephemeral
  • No model training on your data: guaranteed by contract
  • Grounded responses: every answer cites source documents
  • Provenance tracking: full audit trail for AI interactions
  • Data Processing Agreements with all AI sub-processors
Deployment Options

Your infrastructure, your rules.

Choose the deployment model that matches your security and compliance requirements.

Our Cloud

Fully managed on Ageiro infrastructure. AWS-hosted with multi-region availability, automated backups, and 99.5% uptime SLA. Fastest time to value.

Ageiro manages ~90% of the stack

Your Cloud

Deployed within your AWS, Azure, or GCP environment. Your data never leaves your tenancy. Shared responsibility model with Ageiro managing the application layer.

~50/50 shared responsibility

On-Premise

Complete network isolation within your own data center or private cloud. This is not a standard, self-serve option. We scope it with you case by case, so please contact us for further details.

Scoped with you before anything is agreed

Vulnerability Disclosure

Responsible disclosure process.

We welcome responsible security research. If you discover a vulnerability, please follow our disclosure process.

1

Report

Submit vulnerability details to security@ageiro.global with a clear description and reproduction steps.

2

Acknowledge

We acknowledge receipt within 2 business days and assign a severity classification.

3

Investigate

Our security team investigates, validates, and develops a fix. We keep you updated on progress.

4

Resolve

We deploy the fix, verify the resolution, and notify the reporter. Critical issues are addressed within 72 hours.

Report vulnerabilities to

security@ageiro.global

Please do not disclose vulnerabilities publicly until we have resolved the issue.

FAQ

Security questions.

For Our Cloud deployments, data is stored in AWS regions of your choice (UK, EU, US). For Your Cloud and On-Premise, data stays entirely within your infrastructure and never leaves your network.
Ageiro does not access your project data. In Our Cloud deployments, data is encrypted at rest and in transit. Support access requires explicit customer approval and is fully audited.
ARK enforces zero data retention with all AI providers. Your documents and queries are never used to train models. All AI interactions are ephemeral and governed by our data processing agreements.
Not yet. Our first independent penetration test is scheduled as part of our certification program. When it completes, reports will be available to customers under NDA. Until then we are happy to walk your security team through our controls and our internal testing practices.
Ageiro is running a formal certification program for ARK, with independent audit scheduled for September 2026. ARK supports SOC 2 Type II for security and availability, and ISO 42001 for AI management. ARK is GDPR compliant today, and Ageiro is registered with the UK ICO. We do not hold ISO 27001 or Cyber Essentials Plus, and they are not on our certification roadmap. We are happy to share our control documentation and audit timeline on request.
Yes. ARK is fully compliant with the EU General Data Protection Regulation, including data processing agreements with every sub-processor. Customers choose their data residency region, ARK enforces strict per-customer data isolation, and Ageiro is registered with the UK ICO as a data processor and controller.
On-premise deployment is not a standard, self-serve option. We scope it with you case by case, so please contact us for further details. Our two standard options are Our Cloud, a fully managed service on Ageiro infrastructure, and Your Cloud, deployed inside your own AWS, Azure, or GCP tenancy so your data never leaves your environment.
Get Started

Questions about security?

Our security team is happy to discuss your specific requirements and compliance needs.