Security at Aminyx
How we protect workspace data, agent workflows, and customer operations on the platform.
How we secure the platform
Defense in depth across infrastructure, application, and operations.
Encryption in transit
TLS 1.2+ for all client and API traffic.
Encryption at rest
Workspace data encrypted on enterprise cloud infrastructure.
Least-privilege access
Role-based access inside the product; production access is restricted and audited.
Resilient infrastructure
Redundant hosting, automated backups, and monitored uptime.
Security testing
Regular vulnerability assessment and dependency monitoring.
Incident response
Documented process for detection, containment, and customer communication.
Standards and certifications
We document our posture honestly — including work in progress.
GDPR
Data protection practices aligned with EU requirements
SOC 2 Type II
Independent security audit — in progress
ISO 27001
Information security management — planned
PCI DSS
Applicable when payment features are enabled
AI and agent security
Agent features are scoped to your workspace context. We design workflows so:
- Private workspace data is not exposed to other customers
- Third-party model calls use contractual data-processing terms
- You control what content is sent to generation and outreach agents
- Outputs are logged for audit within your workspace where applicable
Responsible disclosure
Report security vulnerabilities responsibly. We acknowledge valid reports and work to remediate quickly.
security@aminyx.biz