Security & compliance

The secure way to put AI in front of your customers

Aide is SOC 2 Type II certified and GDPR and HIPAA compliant. Every conversation runs on enterprise-grade infrastructure, every action follows procedures your team approves, and every decision is logged for audit.Hosted on Microsoft Azure. Models run at zero data retention on enterprise APIs.
SOC 2 Type IIGDPRHIPAA
Certifications

Compliance your vendor review can verify

Agentic AI reads customer data and acts on it. That makes compliance a precondition to deployment, not a checkbox. Aide adheres to the highest standards of enterprise security.

SOC 2 Type II

An independent auditor verified that Aide's security controls, from data handling and access control to incident response, operated effectively over an extended monitoring period under the AICPA's SOC 2 standard. The report stays current through recurring audits.

GDPR

For businesses serving customers in the UK and EU, Aide processes personal data in line with GDPR: lawful processing, data subject rights, and consumer privacy protections in how the platform handles every conversation.

HIPAA

For healthcare organizations, Aide is HIPAA compliant: protected health information is handled with the safeguards the regulation demands, so teams responsible for patient data can use AI without putting it at risk.

Data protection

Your customers' data, protected at every layer

Every conversation is a person who trusted your business with their name, their address, their order history. Aide is built to keep that trust.

Hosted on Microsoft AzureAide runs on Microsoft Azure (US East 2) enterprise infrastructure, the same cloud your security team already knows how to evaluate.
Zero data retentionLarge language models run at zero data retention on enterprise APIs. Model providers operate under zero-data-retention agreements: the conversations they process are not stored or used to train models.
Private cloud deploymentsAide can be provisioned in public or private clouds for sovereign AI deployments where data residency requirements demand it.
Data processing agreementA standing DPA governs how Aide processes personal data on your behalf, including confidentiality obligations and an up-to-date list of sub-processors. Read the DPA →

Security documentation

For security questionnaires, or vendor review documentation, contact our team. Our data processing agreement and privacy policy are available online.

Frequently asked questions

Yes. Aide is SOC 2 Type II certified. An independent auditor verified that Aide's security controls operated effectively over an extended monitoring period under the AICPA's SOC 2 standard, and the report stays current through recurring audits. Contact support@aide.app for the report.

Yes. For businesses serving customers in the UK and EU, Aide processes personal data in line with GDPR requirements: lawful processing, data subject rights, and consumer privacy protections in how the platform handles every conversation. A data processing agreement is available online.

Yes. For healthcare organizations, Aide handles protected health information with the safeguards HIPAA demands, so teams responsible for patient data can deploy AI agents without putting it at risk.

Aide is hosted on Microsoft Azure (US East 2). For sovereign AI deployments with strict data residency requirements, Aide can be provisioned in public or private clouds.

No. Aide's large language models run at zero data retention on enterprise APIs. Model providers operate under zero-data-retention agreements, so the conversations they process are not stored by the provider or used to train their models.

The Agent Governance Engine bounds every word and action: Aide executes only the procedures your team writes and approves, presents only the options configured for the account state, acts only when it is certain, and escalates the rest to a person with full context. Automation is deployed per intent at the level you choose: none, human-in-the-loop, or fully agentic.

Yes. The Action Trace records every automated action: which intent was recognized, which procedure ran, and what was done on the account. Per conversation and across the whole operation, so a question from an auditor, a regulator, or a partner gets an answer backed by the record.

Contact support@aide.app for security documentation, completed questionnaires, and the SOC 2 report. Our data processing agreement, privacy policy, and terms are published online.

Deploy AI agents your security team can sign off on

SOC 2 Type II certified, GDPR and HIPAA compliant, governed by the procedures you approve, and logged for audit.

Get a demo
We use cookies to enhance your Aide experience.
by clicking "accept all" you consent to our use of cookies.
Learn more