Tenant boundaries are enforced
Organisation, workspace, project, and membership controls keep each customer’s business context within its authorised boundary.
Security and data
Consulting AIOS is hosted using Vercel and Supabase, whose infrastructure maintains independently audited security and compliance programs, including SOC 2 Type II and ISO/IEC 27001. Consulting AIOS applies tenant-scoped access controls, database row-level security, encrypted provider credentials, audit logging, retention controls, and documented incident-response processes. Consulting AIOS is not currently independently SOC 2 audited or ISO 27001 certified.
Organisation, workspace, project, and membership controls keep each customer’s business context within its authorised boundary.
Supabase row-level security and scoped server operations restrict how tenant data can be read, changed, exported, or deleted.
Customer-supplied AI provider credentials are encrypted before storage and are not displayed in full after submission.
Important access and administrative actions are auditable, with documented retention, deletion, backup, and incident-response processes.
Shared responsibility
Consulting AIOS protects the platform areas within its control. Your organisation remains free to choose the AI provider, account, model, and commercial plan that fit its own policies.
When an organisation connects its own account or API key, it selects the provider, model, plan, and applicable data terms. Consulting AIOS does not control third-party model service terms, retention, training practices, availability, behaviour, or outputs. Customers are responsible for choosing an approved provider and reviewing model output before use. Consulting AIOS remains responsible for the platform controls within its own scope. Review the full service terms.
Before adding sensitive information
No. Consulting AIOS does not itself train a public model on customer workspace content. Processing by the AI provider selected by the customer remains subject to that provider’s account, plan, configuration, and terms.
Customer-supplied provider credentials are encrypted before storage, scoped to the authorised organisation or workspace, and are not displayed in full after submission.
Organisation administrators have data export and lifecycle controls. Retention periods, backups, legal holds, and deletion boundaries are described on the data-retention page.
Detailed notices
Start with confidence