Security and compliance
ISO 27001, DPA, hosting in the EU.
The contracting party is aiio GmbH in Magdeburg. Certified to ISO/IEC 27001, certificate 02260301-01, valid until 4 June 2029. Hosting and storage are within the European Union; processing in the USA covers sign-in depending on the product, error logging, and any AI providers chosen. Data processing under Art. 28 GDPR, including technical and organizational measures.
Documents and agreements.
All of it without a form, without a sales conversation, downloadable directly.
- ISO/IEC 27001 certificatePDF · German/English · EN ISO/IEC 27001:2023 · certificate 02260301-01 · issued 5 June 2026 · valid until 4 June 2029
The certifying body's document. Scope: development, operation and maintenance of cloud-based B2B solutions for organizational modelling, management and analysis.
Download PDFDirect download - Operations and IT security conceptPDF · German · version 3.0 · as of 14 August 2025 · 17 pages
Architecture, roles and permissions, data backup, deletion concept, tenant separation, encryption, logging, contingency plan. Answers most security questionnaires.
Download PDFDirect download - Data processing agreement (DPA)PDF · DE/EN · Art. 28 GDPR
The annex under Art. 28(3) GDPR in the version aiio signs. Includes the technical and organizational measures as an annex.
Download PDFDirect download - List of sub-processorsPDF · DE/EN · valid from 1 August 2026
Who is involved, for what, in which country and on what legal basis. New sub-processors are announced with a four-week objection period.
Download PDFDirect download - General SaaS termsPDF · DE/EN · as of 1 June 2025
Scope of service, availability, terms, remuneration. Plus return and deletion of the data at the end of the contract.
Download PDFDirect download - Functional specificationPDF · German · as of 15 June 2026
Which functions belong to the product — the contractual basis for what is owed.
Download PDFDirect download - General terms of engagementPDF · DE/EN · 8 pages
For rollout, training and workshops. Independent of the SaaS contract.
Download PDFDirect download - Supplier self-disclosure
The procurement questionnaire gets filled in and countersigned. For the common catalogues the answers are already on file.
Send questionnaireOn request - Privacy policy
Processing on this website: purposes, legal bases, retention, data subject rights.
OpenPublic - Register details and representation
Company name, address, register court, HRB number, VAT ID, management.
OpenPublic
A document missing? ask for it →
Where the data sits.
Hosting and storage are in the EU. Three things process in the USA: sign-in depending on the product, error logging, the AI providers only by choice. Operations, development and support run out of one company in Magdeburg — no chain of holdings, no reseller, no offshore provider in between.
- Platform
- Microsoft Azure and AWS, regions within the EUThe tools do not all run in the same environment: depending on the product, Microsoft or AWS operates the data centre environment. Both are listed as sub-processors — Microsoft Ireland Operations and AWS EMEA SARL, place of processing EU. The Azure environment is a dedicated tenant with a Kubernetes cluster, MySQL and Redis in a closed virtual network. Which environment applies to a given product is stated in the hosting and infrastructure data sheet.
- Storage location
- Servers within the European UnionThree exceptions, and they carry different weight: sign-in processes in the USA depending on the product (see the “Sign-in” row below), error logging sits in a European data region controlled by a US company (see “Error logging”), the optional AI functions only where the organization picks a provider outside the EU.
- Encryption
- AES-256 at rest, TLS 1.2+ in transitVirtual disks, backups and snapshots are encrypted — so is internal communication between the services.
- Backup
- Daily, 30 days, geo-redundantAutomatic database backups, replicated into a geographically separate partner region. Backup files are deleted after 30 days, earlier on request.
- Tenant separation
- Every record belongs to exactly one tenantEvery request is filtered on the tenant identifier. The identifier is issued by the authentication service — by Microsoft Entra in the Azure environment — and cannot be altered from within the application.
- Sign-in
- SSO and multi-factor via Entra ID or Clerk — Clerk processes in the USAWhich service applies depends on the product. Clerk Inc. processes sign-in data in the USA, on the basis of the Data Privacy Framework — Clerk is certified — and standard contractual clauses under Art. 46 GDPR; listed that way in Annex 1, section 1.5. Unlike the AI functions there is nothing to switch off here: no sign-in, no use. Password policies and multi-factor stay in the hands of the organization — aiio enforces whatever is configured in its own directory, and stores no credentials.
- Error logging
- Sentry — European data region, controlled from the USAWhat gets recorded is technical error and performance data of the application; user and organization identifiers, IP addresses and requested URLs can occur in it. Content of the process documentation is not transmitted — server-side filtering limits the transfer to what error analysis requires. The operator is Functional Software, Inc. d/b/a Sentry, San Francisco, listed in Annex 1 under section 1.6; the basis is the Data Privacy Framework and standard contractual clauses under Art. 46 GDPR.
- Deletion
- At any time, with a recordAfter deletion, a deletion record goes to the organization. At the end of a contract the data is deleted at the latest on uninstallation, immediately where instructed.
- Export
- PDF, SVG, CSV, Excel, APIProcesses, org charts, process lists, requirements, resources, sites and staff. A change of provider does not founder on the format.
All details in the operations and IT security concept: Download PDF →
What the AI does with the data.
The AI functions are off by default. Only once they have been switched on and a provider selected is any content transmitted — until then nothing leaves the environment.
- Choice of provider
- Made by the organization, not by aiioThe options are OpenAI, OpenAI via Azure, Anthropic, Google Vertex AI, Groq and Mistral. Without an explicit selection, no data goes to any of them. A newly added provider does not change an existing configuration.
- Model training
- Does not happen on customer contentContractually assured for every listed provider: no use of the transmitted content for training or model improvement purposes.
- Personal data
- Is not transmitted to the AI servicesProcessing personal data is not the purpose. Where uploaded documents contain it, it is processed incidentally — aiio recommends pseudonymizing beforehand.
- Data residency
- Frankfurt selectableOpenAI via Azure runs in the Germany West Central region, Google Vertex AI in europe-west3 — both without third-country transfer. Mistral processes within the EEA. OpenAI directly, Anthropic and Groq process in the USA under standard contractual clauses.
- Retention at the provider
- Zero data retention configurableWhere the provider offers it, it is used. Otherwise the contractually agreed period applies — with OpenAI and Mistral up to 30 days for abuse monitoring, with Groq no retention of inference data.
- Transparency
- Its use is visible in the productWherever an AI function is at work, that is apparent to the user. Every statement in a representation leads back to the document it came from.
- Role under the AI Act
- Provider of an AI systemProcess analysis, summarization and versioning fall, by our own assessment, into none of the high-risk categories of the AI Act. The underlying foundation models are subject to the GPAI requirements at their own providers.
Sub-processor agreements.
Every data processing agreement aiio has concluded with a sub-processor is published — including those with the AI providers.
- Amazon Web ServicesDPA · as of 16 February 2026
Hosting and data centre environment. AWS EMEA SARL, Luxembourg, place of processing EU.
Download PDFDirect download - MicrosoftData Protection Addendum
Hosting, authentication and Azure OpenAI services. Microsoft Ireland Operations, Dublin.
OpenPublic - OpenAIDPA · signed
AI provider, usable directly. OpenAI Ireland Ltd., processing in the USA under standard contractual clauses.
Download PDFDirect download - AnthropicDPA · as of 22 September 2023
AI provider. Anthropic Ireland Ltd., processing in the USA under standard contractual clauses, no training on customer content.
Download PDFDirect download - GoogleData Processing Addendum
AI provider Vertex AI. Google Cloud EMEA, processing in the Frankfurt data centre.
OpenPublic - GroqDPA
AI provider. Groq Inc., processing in the USA under standard contractual clauses, inference data is not retained.
Download PDFDirect download - MistralData Processing Addendum
AI provider. Mistral AI SAS, Paris, processing within the EEA.
OpenPublic - ClerkDPA
Authentication platform. Clerk Inc., USA, Data Privacy Framework and standard contractual clauses.
OpenPublic - Aikido SecurityDPA · v1.3 · valid from 1 August 2025
Security monitoring of the cloud infrastructure and of software development. Aikido Security bv, Ghent, Belgium, place of processing EU. What is processed is configuration, source code and telemetry data of the platform; incoming requests are inspected for injection and events are reported to the Aikido cloud with IP addresses. Processing personal data of the client is not the purpose.
Download PDFDirect download - SentryDPA · signed 12 August 2026
Application monitoring and error logging. Functional Software, Inc. d/b/a Sentry, San Francisco, European data region and USA, Data Privacy Framework and standard contractual clauses. User and organization identifiers, IP addresses and requested URLs can occur; content of the process documentation is not transmitted.
Download PDFDirect download - ZohoDPA · signed
Customer data management. Zoho Corporation GmbH, Düsseldorf, processing in Amsterdam and Dublin.
Download PDFDirect download - DATEVDPA · as of 1 January 2025
Customer data management for accounting. DATEV eG, Nuremberg, processing in Germany.
Download PDFDirect download
The complete list with purpose, location and legal basis: Download PDF →
Commitments and limits.
Every commitment here also stands in the contract. Beside it stands where it ends.
Reporting channels.
Someone answers who knows the installation. No outsourced first level in between.
- Security incident
- support@aiio.de · 0391 251 948 63A suspicion is enough. Where personal data is affected, the route from the DPA runs in parallel.
- Vulnerability
- support@aiio.deFrom outside as well. Receipt is confirmed before the finding is resolved.
- Data protection
- via the contact formAccess, rectification and erasure under Art. 15 to 17 GDPR. For existing customers additionally via the body named in the DPA.
- Service disruption
- Monday to Friday, business hoursMonitoring catches most disruptions before they are noticed. Resolution time follows the agreed SLA; whoever reported it is kept informed.
The contracting party.
One company, one register entry, one location — no chain of holding, sales and operating entities.
Klausenerstraße 10a, 39112 Magdeburg. Amtsgericht Stendal, HRB 6552. VAT ID DE 254461500.
Dr. Christian Graup, Knut Köchli, Jobst von Heintze, Lars Bendler. The representation arrangements are recorded in the commercial register.
Certificate 02260301-01, valid until 4 June 2029. The document and its scope are in the documents section.

Entered on 18 June 2007, trading under the name aiio since March 2022. Register entry, location and team unchanged.
Hosting and storage within the European Union, sign-in and error logging partly in the USA. Seat, development and support in Magdeburg.
Institutionally funded since 2024, eight-figure valuation. For the credit check.
Origins, management and advisory board: to the company →
Something missing?
Whatever is not here is either confidential or does not exist. Ask, and you get told which of the two.