AIBODY Trust Center

At AIBODY, we take the security of our and our customer’s valuable data, IP, infrastructure and digital assets with the utmost seriousness. 
trust-center

Cybersecurity

cyber-essentials-novaheart
We understand that in today's rapidly evolving digital landscape, a strong and robust approach to cybersecurity is not just a necessity but a fundamental requirement for the success and sustainability of any technology company. We invest heavily in our comprehensive cybersecurity framework which we regularly audit and improve on.

As a clear and tangible demonstration of AIBODY’s commitment to cybersecurity we maintain a Cyber Essentials official certification by the IASME Consortium. 

The certification provides a robust framework for continuously evaluating and improving our cybersecurity posture, covering elements such as network security, access controls, and malware protection.
Download Certificate

Controls

Our security controls outline how we protect data across infrastructure, organization, product, and privacy—along with each control’s implementation status.
Infrastructure Security
Organizational Security
Product Security
Internal Security Procedures
Data and Privacy
Restricted access to production databases
Access to production databases is limited to authorized personnel with a verified business need and appropriate privileges.

Restricted access to production networks
Privileged access to production networks is granted only to authorized users based on role and business necessity.

Unique authentication enforced
Access to production systems requires unique user authentication, using individual usernames and passwords or approved Secure Shell (SSH) keys.

Encrypted remote access
Remote access to production systems is permitted only through approved, encrypted connections and is restricted to authorized employees.

Log management and monitoring
The company employs centralized log management to detect, analyze, and respond to events that could impact security objectives.

Network segmentation
The production environment is segmented to minimize risk and prevent unauthorized access to customer data.
Employee background checks
Background checks are conducted for all new employees in accordance with applicable laws and regulations.

Contractor confidentiality agreements
All contractors are required to sign a confidentiality agreement prior to engagement.

Employee confidentiality agreements
Employees acknowledge and sign NDA as part of the onboarding process.

Performance evaluations
Managers conduct performance evaluations for their direct reports at least once a year.
Encryption at rest
Customer data stored in company-managed data storage is encrypted at rest.

Control self-assessments
The company performs control self-assessments at least once a year to confirm that security controls are properly designed and operating effectively.

Encryption in transit
Secure transmission protocols are used to encrypt customer data transmitted over public networks.

Vulnerability and system monitoring
The policies define requirements for vulnerability management and continuous system monitoring within IT and Engineering functions.
Configuration management
A configuration management process ensures systems are deployed and maintained in a consistent and secure manner.

Documented organizational structure
The company maintains an up-to-date organizational chart outlining reporting lines and responsibilities.

Defined roles and responsibilities
Information security roles and responsibilities across system design, development, operation, and monitoring are formally documented.

Support and incident reporting
A support system enables users to report incidents, failures, concerns, and other issues to appropriate personnel.

Access provisioning controls
User access to system components is role-based and requires documented approval prior to provisioning.

Customer support resources
Guidelines and technical support resources related to system operations are available to customers.

Service transparency
The company provides clear descriptions of its products and services to both internal and external users.

Risk management objectives
Risk management objectives are defined to support the identification and assessment of risks affecting service commitments.

Risk assessments
Risk assessments are conducted at least once a year, considering environmental, regulatory, technological changes, and potential fraud risks.

Third-party management
Written agreements with vendors and third parties include confidentiality and privacy obligations appropriate to the services provided.
AI and Customer Data

We do not use customer data to train our AI models. Your data is used only to provide and support our services — never for advertising, resale, or unrelated product development.

Customer data deletion
Upon service termination, customer data is securely deleted unless it needs to be stored for the purposes and for the duration required under applicable legislation.

Subprocessors

See the trusted third-party service providers we use to operate AIBODY, what they do, and how they may process limited customer data.
Anthropic-Icon--Streamline-Svg-Logos
Anthropic 
AI model services
openai
OpenAI
AI model services
Amazon Web Services 
Amazon Web Services 
Cloud infrastructure
Google Cloud Platform 
Google Cloud Platform 
Cloud infrastructure and AI model services
Microsoft_logo.svg
Microsoft Corporation
Cloud infrastructure, email, collaboration, and document storage services provided via Microsoft Azure and Microsoft 365.
Onseo Affiliates Limited
Onseo Affiliates Limited
An ISO 27001 certified provider of IT infrastructure.

FAQs

Find clear, straightforward answers about how we protect data, manage access, work with subprocessors, and meet security expectations.
Data Usage & Residency
Security Standards & Compliance

Does AIBODY sell or share user data with third parties?

AIBODY does not sell your personal data. For details on data sharing practices, please refer to Privacy Policy: https://aibody.io/privacy-policy/


Where is the data stored?

Data storage location: Amazon Web Services servers located in London 


Who are AIBODY's sub-processors? 

A list if our sub-processors is publicly available at https://aibody.io/aibody-trust-center/#section-107-31

 

What security certifications does AIBODY hold? 

AIBODY performs a regular (annual) Cyber Essential assessment. 
Our IT infrastructure provider, Onseo Affiliates, holds ISO/IEC 27001:2022 (Information Security Management System) compliance certificate.

Issued certificates you could find on https://aibody.io/aibody-trust-center/#section-15-31

  

What security measures does AIBODY implement? 

Encryption: Data encrypted in transit (TLS) and at rest (AES-256) 

Access Controls: Role-based permissions, MFA required for administrators 
Data Isolation: separate account per user 
Monitoring: Continuous security monitoring, regular vulnerability assessments 

Book a Demo

Book a live demo and explore how our real-time simulations can transform your clinical training or research.

    Web design & development by AUG.Global

    crossmenuchevron-down-circle