Security foundations for business-critical context.

Consulting AIOS is hosted using Vercel and Supabase, whose infrastructure maintains independently audited security and compliance programs, including SOC 2 Type II and ISO/IEC 27001. Consulting AIOS applies tenant-scoped access controls, database row-level security, encrypted provider credentials, audit logging, retention controls, and documented incident-response processes. Consulting AIOS is not currently independently SOC 2 audited or ISO 27001 certified.

Tenant boundaries are enforced

Organisation, workspace, project, and membership controls keep each customer’s business context within its authorised boundary.

Database access is policy-controlled

Supabase row-level security and scoped server operations restrict how tenant data can be read, changed, exported, or deleted.

Provider credentials are encrypted

Customer-supplied AI provider credentials are encrypted before storage and are not displayed in full after submission.

Operations remain accountable

Important access and administrative actions are auditable, with documented retention, deletion, backup, and incident-response processes.

A clear boundary between our platform and your chosen AI provider.

Consulting AIOS protects the platform areas within its control. Your organisation remains free to choose the AI provider, account, model, and commercial plan that fit its own policies.

What Consulting AIOS controls

  • Tenant, workspace, project, and role boundaries
  • Database row-level security and scoped server access
  • Encryption of customer-supplied provider credentials
  • Audit, retention, deletion, and incident-response controls

What your organisation chooses

  • The connected AI provider, account, subscription, or API key
  • The model and provider plan used to process each request
  • Whether that provider’s terms suit the information submitted
  • Who reviews and approves AI-assisted outputs before use

When an organisation connects its own account or API key, it selects the provider, model, plan, and applicable data terms. Consulting AIOS does not control third-party model service terms, retention, training practices, availability, behaviour, or outputs. Customers are responsible for choosing an approved provider and reviewing model output before use. Consulting AIOS remains responsible for the platform controls within its own scope. Review the full service terms.

Start with the minimum context required for a useful answer.

Does Consulting AIOS train a public model?

No. Consulting AIOS does not itself train a public model on customer workspace content. Processing by the AI provider selected by the customer remains subject to that provider’s account, plan, configuration, and terms.

How are customer provider keys handled?

Customer-supplied provider credentials are encrypted before storage, scoped to the authorised organisation or workspace, and are not displayed in full after submission.

Can organisation data be exported or deleted?

Organisation administrators have data export and lifecycle controls. Retention periods, backups, legal holds, and deletion boundaries are described on the data-retention page.

Review the policies relevant to your use.

Put the controls to work in a bounded business scenario.