Security
What we operate, what we do not have, and how to tell us about a problem.
AIConscius is a service of AISocius AB (in formation). Company registration details will be published here once incorporation is complete.
Contact: privacy@aisocius.com
Last updated: 2026-07-25
What we do not have
We hold no security certification. We are not SOC 2 audited, not ISO/IEC 27001 certified, and we do not hold a third-party attestation of any kind. An earlier version of this site claimed otherwise; that was wrong and has been removed.
If your procurement process requires an audited certification today, we are not yet the right supplier, and we would rather tell you that than find out during your security review.
What we do operate
Traffic is served over TLS. Data is encrypted in transit and at rest by our hosting and database providers. Authentication and session handling are provided by our managed identity provider rather than implemented by us.
Access between organisations is separated at the database layer, and the separation is tested — including with tests written specifically to try to read across the boundary and fail.
Actions that change an assessment are recorded in an audit trail with the actor, the time and the previous state. That exists for defensibility, and it doubles as a security control.
Where we are
Reporting a vulnerability
Please write to security@aisocius.com with enough detail to reproduce the issue. We will acknowledge within three working days and tell you what we intend to do.
We will not pursue you for good-faith research that stays within a test account you control, does not access or modify other people's data, does not degrade the service, and gives us reasonable time to fix the issue before disclosure. Please do not run automated scanners against production without asking us first.