Security and compliance
ISO 27001, DPA, hosting in the EU
The contracting party is aiio GmbH in Magdeburg. Certified to ISO/IEC 27001, certificate 02260301-27-01, valid until 4 June 2029. Hosting and storage are within the European Union; processing in the USA covers sign-in via Clerk, error logging, and any AI providers chosen. Data processing under Art. 28 GDPR, including technical and organizational measures.
Documents and agreements
All of it without a form, without a sales conversation, downloadable directly.
- ISO/IEC 27001 certificatePDF · English · EN ISO/IEC 27001:2023 · certificate 02260301-27-01 · issued 5 June 2026 · valid until 4 June 2029
The certifying body's document. Scope: development, operation and maintenance of cloud-based B2B solutions for organizational modelling, management and analysis.
Download PDFDirect download - Operations and IT security conceptPDF · German · version 2.0 · as of 10 September 2026 · 20 pages
Architecture, roles and permissions, data backup, deletion concept, tenant separation, encryption, logging, contingency plan, AI compliance - for aiio Process Collector. Answers most security questionnaires.
Download PDFDirect download - Data processing agreement (DPA)PDF · DE/EN · Art. 28 GDPR · valid from 1 June 2026
The annex under Art. 28(3) GDPR in the version aiio signs. Includes the technical and organizational measures as an annex.
Download PDFDirect download - List of sub-processorsPDF · DE/EN · valid from 1 August 2026
Who is involved, for what, in which country and on what legal basis. New sub-processors are announced with a four-week objection period.
Download PDFDirect download - General SaaS termsPDF · DE/EN · as of 1 June 2025
Scope of service, availability, terms, remuneration. Plus return and deletion of the data at the end of the contract.
Download PDFDirect download - Functional specificationPDF · German · as of 15 June 2026
Which functions belong to the product - the contractual basis for what is owed.
Download PDFDirect download - General terms of engagementPDF · DE/EN · 8 pages
For rollout, training and workshops. Independent of the SaaS contract.
Download PDFDirect download - Supplier self-disclosure
The procurement questionnaire gets filled in and countersigned. For the common catalogues the answers are already on file.
Send questionnaireOn request - Privacy policy
Processing on this website: purposes, legal bases, retention, data subject rights.
OpenPublic - Register details and representation
Company name, address, register court, HRB number, VAT ID, management.
OpenPublic
A document missing? ask for it →
Where the data sits
Hosting and storage are in the EU. Three things process in the USA: sign-in via Clerk, error logging, the AI providers only by choice. Operations, development and support run out of one company in Magdeburg - no chain of holdings, no reseller, no offshore provider in between.
- Platform
- Amazon Web Services (AWS), Frankfurt region (eu-central-1)The application, database and delivery of static content run in a dedicated AWS account: Amazon EKS (Kubernetes) for the application, Amazon Aurora PostgreSQL for the database, CloudFront/S3 for static content. The hosting location is operated by AWS EMEA SARL, Luxembourg, listed as a sub-processor. A few supplementary services - error logging, security monitoring, AI functions - have their own places of processing, see the respective rows and the sub-processor list.
- Storage location
- Servers within the European UnionThree exceptions, and they carry different weight: sign-in via Clerk processes in the USA (see the “Sign-in” row below), error logging sits in a European data region controlled by a US company (see “Error logging”), the optional AI functions only where the organization picks a provider outside the EU.
- Encryption
- AES-256 at rest, TLS 1.2+ in transitEncrypted with AES-256 via AWS Key Management Service (KMS): virtual disks (Amazon EBS), backups and snapshots. Encrypted with TLS 1.2 or higher: the connection to the end user, as well as the internal communication between services within the Kubernetes cluster and to the database.
- Backup
- Continuous, 30 days, six-fold redundantAmazon Aurora backs up transaction logs continuously rather than in daily snapshots - that enables point-in-time recovery to any second within the 30-day retention period. The storage volumes are replicated six-fold across three availability zones in the Frankfurt region; the production database cluster runs across two of them. If the primary instance fails, a reader instance takes over within 30 seconds.
- Tenant separation
- Every record belongs to exactly one tenantEvery user is a member of one or more organizations at the identity service Clerk, and every organization has its own database. Requests are routed by organization membership; it is issued by Clerk, carried in the authenticated session context, and cannot be altered from within the application.
- Sign-in
- SSO and multi-factor via Clerk - processes in the USASign-in runs entirely through the identity service Clerk, either by email or via an OAuth provider such as Entra ID. Clerk Inc. processes sign-in data in the USA, on the basis of the Data Privacy Framework - Clerk is certified - and standard contractual clauses under Art. 46 GDPR; listed that way in Annex 1, section 1.5. Unlike the AI functions there is nothing to switch off here: no sign-in, no use. Password policies and multi-factor stay in the hands of the organization: anyone signing in via an OAuth provider keeps that provider's own policies in force; for direct email sign-in, Clerk enforces them. aiio stores no credentials.
- Error logging
- Sentry - European data region, controlled from the USAWhat gets recorded is technical error and performance data of the application; user and organization identifiers, IP addresses and requested URLs can occur in it. Content of the process documentation is not transmitted - server-side filtering limits the transfer to what error analysis requires. The operator is Functional Software, Inc. d/b/a Sentry, San Francisco, listed in Annex 1 under section 1.6; the basis is the Data Privacy Framework and standard contractual clauses under Art. 46 GDPR.
- Deletion
- At any time, with a recordAfter deletion, a deletion record goes to the organization. At the end of a contract the organization's database is deleted within 30 days, and its identity-service account in the same step. Encrypted data fragments remain in the automated backups for technical reasons until that same 30-day retention window elapses - this applies to an early deletion request too: active systems are cleared immediately, backups only once the window closes.
- Export
- PDF, SVG, CSV, Excel, APIProcesses, org charts, process lists, requirements, resources, sites and staff. A change of provider does not founder on the format.
All details in the operations and IT security concept: Download PDF →
What the AI does with the data
The AI functions are off by default. Only once they have been switched on and a provider selected is any content transmitted - until then nothing leaves the environment.
- Choice of provider
- Made by the organization, not by aiioThe options are OpenAI, OpenAI via Azure, Anthropic, Google Vertex AI, Groq and Mistral. Without an explicit selection, no data goes to any of them. A newly added provider does not change an existing configuration.
- Model training
- Does not happen on customer contentContractually assured for every listed provider: no use of the transmitted content for training or model improvement purposes.
- Personal data
- Is not transmitted to the AI servicesProcessing personal data is not the purpose. Where uploaded documents contain it, it is processed incidentally - aiio recommends pseudonymizing beforehand.
- Data residency
- Frankfurt selectableOpenAI via Azure runs in the Germany West Central region, Google Vertex AI in europe-west3 - both without third-country transfer. Mistral processes within the EEA. OpenAI directly, Anthropic and Groq process in the USA under standard contractual clauses.
- Retention at the provider
- Zero data retention configurableWhere the provider offers it, it is used. Otherwise the contractually agreed period applies - with OpenAI and Mistral up to 30 days for abuse monitoring, with Groq no retention of inference data.
- Transparency
- Its use is visible in the productWherever an AI function is at work, that is apparent to the user. Every statement in a representation leads back to the document it came from.
- Role under the AI Act
- Provider of an AI systemProcess analysis, summarization and versioning fall, by our own assessment, into none of the high-risk categories of the AI Act. The underlying foundation models are subject to the GPAI requirements at their own providers.
Sub-processor agreements
Every data processing agreement aiio has concluded with a sub-processor is published - including those with the AI providers.
- Amazon Web ServicesDPA · as of 16 February 2026
Hosting and data centre environment. AWS EMEA SARL, Luxembourg, place of processing EU.
Download PDFDirect download - MicrosoftData Protection Addendum
Azure OpenAI as a selectable AI option, Entra ID as a selectable OAuth sign-in path via Clerk. Microsoft Ireland Operations, Dublin.
OpenPublic - OpenAIDPA · signed
AI provider, usable directly. OpenAI Ireland Ltd., processing in the USA under standard contractual clauses.
Download PDFDirect download - AnthropicDPA · as of 22 September 2023
AI provider. Anthropic Ireland Ltd., processing in the USA under standard contractual clauses, no training on customer content.
Download PDFDirect download - GoogleData Processing Addendum
AI provider Vertex AI. Google Cloud EMEA, processing in the Frankfurt data centre.
OpenPublic - GroqDPA
AI provider. Groq Inc., processing in the USA under standard contractual clauses, inference data is not retained.
Download PDFDirect download - MistralData Processing Addendum
AI provider. Mistral AI SAS, Paris, processing within the EEA.
OpenPublic - ClerkDPA
Authentication platform. Clerk Inc., USA, Data Privacy Framework and standard contractual clauses.
OpenPublic - Aikido SecurityDPA · v1.3 · valid from 1 August 2025
Security monitoring of the cloud infrastructure and of software development. Aikido Security bv, Ghent, Belgium, place of processing EU. What is processed is configuration, source code and telemetry data of the platform; incoming requests are inspected for injection and events are reported to the Aikido cloud with IP addresses. Processing personal data of the client is not the purpose.
Download PDFDirect download - SentryDPA · signed 12 August 2026
Application monitoring and error logging. Functional Software, Inc. d/b/a Sentry, San Francisco, European data region and USA, Data Privacy Framework and standard contractual clauses. User and organization identifiers, IP addresses and requested URLs can occur; content of the process documentation is not transmitted.
Download PDFDirect download - ZohoDPA · signed
Customer data management. Zoho Corporation GmbH, Düsseldorf, processing in Amsterdam and Dublin.
Download PDFDirect download - DATEVDPA · as of 1 January 2025
Customer data management for accounting. DATEV eG, Nuremberg, processing in Germany.
Download PDFDirect download
The complete list with purpose, location and legal basis: Download PDF →
What we commit to - and where it ends
Every commitment here also stands in the contract. Beside it stands where it ends.
Reporting channels
Someone answers who knows the installation. No outsourced first level in between.
- Security incident
- support@aiio.de · 0391 251 948 63A suspicion is enough. Where personal data is affected, the route from the DPA runs in parallel.
- Vulnerability
- support@aiio.deFrom outside as well. Receipt is confirmed before the finding is resolved.
- Data protection
- via the contact formAccess, rectification and erasure under Art. 15 to 17 GDPR. For existing customers additionally via the body named in the DPA.
- Service disruption
- Monday to Friday, business hoursMonitoring catches most disruptions before they are noticed. Resolution time follows the agreed SLA; whoever reported it is kept informed.
The contracting party
One company, one register entry, one location - no chain of holding, sales and operating entities.
Klausenerstraße 10a, 39112 Magdeburg. Amtsgericht Stendal, HRB 6552. VAT ID DE 254461500.
Dr. Christian Graup, Knut Köchli, Jobst von Heintze, Lars Bendler. The representation arrangements are recorded in the commercial register.
Certificate 02260301-27-01, valid until 4 June 2029. The document and its scope are in the documents section.

Entered on 18 June 2007, trading under the name aiio since March 2022. Register entry, location and team unchanged.
Hosting and storage within the European Union, sign-in and error logging partly in the USA. Seat, development and support in Magdeburg.
Institutionally funded since 2024, eight-figure valuation. For the credit check.
Origins, management and advisory board: to the company →
Something missing?
Whatever is not here is either confidential or does not exist. Ask, and you get told which of the two.