Legal & trust
Security Overview
A draft, factual overview of implemented safeguards and controls that still require operational verification.
Document status: approved. Proposed approval date: 2026-09-23.
Implemented product safeguards
- Tenant-scoped database access with row-level security controls.
- Separate privileged and tenant-scoped database connection roles in production configuration.
- Encrypted storage for operator-managed integration credentials.
- Signed OAuth state validation and scoped authorization checks.
- Document quarantine and malware scanning when production document storage is enabled.
- Human review and approval controls for generated content.
Operational controls still to verify
- Production monitoring, alerting, backup restoration, incident exercises, and access reviews.
- Vendor due diligence, subprocessor records, recovery objectives, and evidence retention.
- External penetration testing and any independent assurance program.
No certification claim
BrandIntel does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or another independent certification on the basis of this draft page.
Report a security concern
Send security reports to security@aivedix.com. Do not include sensitive customer data until a secure exchange method has been agreed.