Your organization's memory deserves real protection.
Every credential AIAN stores, every webhook it accepts, and every query it runs is scoped, verified, and isolated by design — not as an afterthought.
What's actually protecting your data
No vague promises — these are the mechanisms built into AIAN today.
Encrypted credentials at rest
Every access and refresh token AIAN stores for Slack, GitHub, Jira, and Zoom is encrypted before it ever touches the database — never saved as plain text.
Role-based access control
Every backend request is checked three times: is the user authenticated, do they belong to the organization, and do they hold the specific permission the action requires.
Verified webhooks
Incoming webhooks from every connected provider are validated against their cryptographic signature before AIAN accepts a single byte of payload.
Isolated by organization
Every query is scoped to a single organization at the database layer. One organization's knowledge graph is never reachable from another's session.
Found something? Here's what happens next
Report
Send us the details privately by email. Please avoid publicly disclosing the issue until we've had a chance to address it.
Acknowledge
We confirm we've received your report and begin an initial assessment of its scope and severity.
Investigate & fix
We reproduce the issue, work on a fix, and keep you updated on progress as we go.
Disclose
Once resolved, we coordinate with you on how and when to share details publicly, if at all.
Found a vulnerability?
We take every report seriously and do our best to respond as quickly as we can. Please report security issues privately rather than through public channels.