Trust center
Trust center
The current state of our controls, certifications, sub-processors and service commitments — published, not promised on request.
Trust center
This page states where ÆTERION stands today: which security controls are in operation, which certifications are in progress, which sub-processors handle data, and what our service commitments are. When a status changes, this page changes with it, and the change is dated.
Certification status
- ISO/IEC 27001
- Control set implemented; certification audit in preparation. Status updated as the audit progresses.
- ISO/IEC 42001
- AI management system implemented following the standard; certification in preparation.
- SOC 2 Type II
- Planned once the ISO programme completes. No report is available today.
- EU AI Act readiness
- Platform features for classification, oversight, logging and documentation are in production use.
Data and sub-processors
- Hosting: Swiss or EU regions, chosen per customer environment.
- Model providers: called through the gateway under terms that exclude training on customer content.
- A current sub-processor list is provided with the contract and updated with notice before any change.
- Customer data is deleted on termination according to the retention terms agreed in the contract.
Service commitments
- Availability
- Service levels are defined per plan and stated in the contract, with measured uptime reported to customers.
- Support
- Named support contacts with response times by severity.
- Incident notification
- Security incidents affecting customer data are notified without undue delay, with a written follow-up report.
- Exit
- Process definitions, policies and traces are exportable in open formats at any time.
FAQ
Can we receive your documentation under NDA?
Yes. Security architecture documents, penetration-test summaries and policy documents are shared under a mutual NDA.
How do we report a vulnerability?
Write to hallo@aeterion.tech with the details. We acknowledge receipt and keep the reporter informed until the issue is closed.
Ask for the full documentation pack
Security architecture, sub-processor list and policy documents, shared under NDA.
