Trust & Security
A security company has to earn trust. Here is how we protect your data and the access you give us.
Last updated: 3 October 2026
Your data stays yours
Aithsense works on top of the security tools you already run. Your logs stay in your SIEM. We query them with access you grant and control, and you can revoke it at any time.
When the Aithsense agent runs inside your network, hunts execute locally and only results leave your perimeter. Customer data is used only to deliver the service to that customer.
Access control
- Integrations use scoped, least-privilege credentials, read-only wherever the task allows.
- Staff access to customer environments is limited to the people who need it, protected by multi-factor authentication and reviewed regularly.
- Every automated response runs inside approval boundaries you configure: act automatically, require a human, or escalate.
Encryption
Data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest in our storage. Connections between the agent and the platform are mutually authenticated.
Every action is auditable
Every finding and every action taken by our agents is logged with who or what took it, why, and on what evidence. Response actions have a documented undo path, so nothing the platform does is a black box or a one-way door.
Infrastructure
Our platform runs on established cloud infrastructure. Public endpoints sit behind Cloudflare, origin servers accept traffic only from Cloudflare, and our public APIs are rate limited. Production systems are monitored around the clock.
Secure development
- All code changes are peer reviewed before release.
- Dependencies are tracked and scanned for known vulnerabilities.
- Secrets are kept out of source code and rotated when people or systems change.
Frameworks and privacy
We design our controls around recognised frameworks, including ISO/IEC 27001 and the NCSC Cloud Security Principles. We support our customers' UK GDPR obligations with a data processing agreement, and our Privacy Policy covers personal data collected through this website.
Incident response
We run security operations for a living, and we apply the same discipline to ourselves. If an incident affects customer data, we will notify affected customers without undue delay and share what we know, what we are doing and what they should do.
Reporting a vulnerability
If you believe you have found a security vulnerability in Aithsense, please email inquiries@aithsense.ai with “Security” in the subject line and enough detail for us to reproduce it. Please give us reasonable time to fix it before disclosing it publicly. We will acknowledge your report and keep you updated.
Security questionnaires
Customers and prospects can request more detail on our security practices, or send us their security questionnaire, at inquiries@aithsense.ai.