Trust Center

Last updated: April 2026

Public platform security summary

AIKIT RESEARCH, S.A. operates as an artificial intelligence research and development laboratory under the most demanding professional, scientific, and information security standards of the sector. This document provides a public summary of the principal security measures of the AiKit platform. The detailed technical and organizational measures are set out in Annex III of the DPA.

1. Architecture and deployment

1.1. Hosting and data residency

The AiKit platform is hosted on certified cloud infrastructure (Microsoft Azure and providers in accordance with Annex II of the DPA), with data centers located in the European Union for the standard deployment.

1.2. Deployment models

AIKIT RESEARCH, S.A. offers, depending on the plan contracted:

  • Multi-tenant SaaS within the EU.
  • Dedicated deployment for Enterprise Clients with specific requirements.
  • Optional global deployment configuration where the Client requires capabilities not available within the EU, expressly activated.

2. Encryption

  • Encryption in transit: TLS 1.3 for all communications between the Client and the platform, as well as between the internal components of the service.
  • Encryption at rest: AES-256 or equivalent for Client data stored on a persistent basis, including backups.
  • Centralized management of keys and secrets with a rotation policy.

3. Access control

  • Robust user authentication through individual credentials and multi-factor authentication (MFA).
  • Role-based access control (RBAC) model applying the principle of least privilege.
  • Administrative access under Zero-Trust principles.
  • Periodic review of access rights.

4. Isolation and segregation

  • Logical segregation of each Client's data through unique identifiers and access controls at the application and storage levels.
  • Strict separation between the development, staging, and production environments.

5. Monitoring and response

  • Continuous monitoring of service availability and performance.
  • Centralized log and alert management (SIEM).
  • Documented incident response procedure.
  • Notification to the Client of security breaches without undue delay and, in any event, within seventy-two (72) hours of becoming aware of them, in accordance with the DPA.

6. Continuity and recovery

  • Automated backups at a frequency appropriate to the risk, encrypted and stored in the same geographic region as the operation.
  • Periodic recovery testing.
  • Documented business continuity and recovery plan.

7. Security testing

  • Automated vulnerability scans within the development lifecycle and across infrastructure.
  • Periodic penetration testing (pentests), at least annually, conducted by independent third parties.
  • Public responsible vulnerability disclosure policy (Vulnerability Disclosure Policy).

8. Vendor management

AIKIT RESEARCH, S.A. relies on a limited set of sub-processors, all of which are bound by data processing agreements that mirror the data protection obligations assumed by AIKIT RESEARCH, S.A. The up-to-date list is published in Annex II of the DPA.

9. No-training commitment

AIKIT RESEARCH, S.A. does not use the Client's personal data, the Inputs, or the Outputs to train its own artificial intelligence models or those of third parties, nor for any purpose other than what is strictly necessary to perform the service. This commitment is passed through contractually to model providers in accordance with clause 2.2 and Annex I of the DPA.

10. Alignment with international standards

AIKIT RESEARCH, S.A. operates an information security management system aligned with the principles of:

  • ISO/IEC 27001 (Information Security Management System).
  • ISO/IEC 27701 (Privacy Information Management System).
  • ISO/IEC 42001 (Artificial Intelligence Management System).
  • SOC 2 Trust Services Criteria.

AIKIT RESEARCH, S.A. continuously assesses the appropriateness of obtaining formal certifications under such standards.

11. Downloadable documentation

The following documents are available in a version pre-signed by AIKIT RESEARCH, S.A. Contracting the platform entails their acceptance by use, without prejudice to their download:

13. Authorities and e-evidence requests

Requests from competent authorities and legally binding electronic evidence (e-evidence) requests must be addressed to admin@aikit.io. AIKIT RESEARCH, S.A. will handle requests that meet the applicable legal requirements and maintains a designated point of contact for their receipt.

14. Incident reporting and inquiries

15. Updates

The information contained in this document is updated periodically. The version in force is available on the AiKit Trust Center page.