Security
Last Updated: January 2025
Our Commitment to Security
At AIM, security is not an afterthought. It's built into everything we do. We understand that you trust us with your personal information, task data, and financial commitments. We take this responsibility seriously and have implemented comprehensive security measures to protect your data.
Data Encryption
Encryption in Transit
All data transmitted between your device and our servers is encrypted using industry-standard TLS 1.3 (Transport Layer Security):
- HTTPS protocol for all web communications
- Certificate pinning for mobile applications
- Secure WebSocket connections for real-time features
- End-to-end encryption for sensitive operations
Encryption at Rest
Your data is encrypted when stored on our servers:
- AES-256 encryption for all stored data
- Encrypted database backups
- Encrypted file storage
- Secure key management using industry best practices
Authentication and Access Control
User Authentication
- Secure password hashing using bcrypt
- Multi-factor authentication (MFA) support
- OAuth 2.0 integration for social login
- Session management with secure tokens
- Automatic session expiration
- Account lockout after failed login attempts
Internal Access Controls
- Role-based access control (RBAC) for employees
- Principle of least privilege
- Multi-factor authentication required for all staff
- Comprehensive audit logging of access
- Regular access reviews
Infrastructure Security
Cloud Infrastructure
We leverage Google Cloud Platform and Firebase, which provide:
- SOC 2 Type II certified infrastructure
- ISO 27001 certified data centers
- Physical security with 24/7 monitoring
- DDoS protection and mitigation
- Automatic failover and redundancy
- Geographic data replication
Network Security
- Firewalls and intrusion detection systems
- Network segmentation
- Virtual Private Cloud (VPC) isolation
- Regular network security assessments
Application Security
Secure Development Practices
- Security by design principles
- Regular code reviews focusing on security
- Automated security scanning in CI/CD pipeline
- Dependency vulnerability scanning
- OWASP Top 10 compliance
Input Validation and Sanitization
- Server-side validation of all inputs
- Protection against SQL injection
- Cross-Site Scripting (XSS) prevention
- Cross-Site Request Forgery (CSRF) protection
- Rate limiting to prevent abuse
Payment Security
Financial transactions are handled with the highest security standards:
- PCI DSS compliant payment processing through Stripe
- We never store credit card numbers on our servers
- Tokenization of payment information
- 3D Secure authentication for card payments
- Fraud detection and prevention systems
- Secure webhooks for payment notifications
Monitoring and Incident Response
24/7 Monitoring
- Real-time security monitoring and alerting
- Automated threat detection
- Log aggregation and analysis
- Anomaly detection systems
- Uptime monitoring and health checks
Incident Response
We have a comprehensive incident response plan:
- Dedicated security incident response team
- Documented procedures for various incident types
- Rapid response and containment protocols
- Post-incident analysis and improvements
- User notification in case of data breaches (as required by law)
Data Backup and Recovery
- Automated daily backups of all data
- Encrypted backup storage
- Geographic backup redundancy
- Regular backup restoration testing
- Point-in-time recovery capabilities
- Disaster recovery plan with defined RPO and RTO
Security Assessments
We regularly evaluate and improve our security posture:
- Annual third-party security audits
- Penetration testing by security professionals
- Vulnerability assessments
- Security code reviews
- Compliance assessments (GDPR, SOC 2, etc.)
Employee Security
- Background checks for all employees
- Security awareness training
- Confidentiality agreements
- Secure device management policies
- Regular security updates and training
Your Role in Security
Security is a shared responsibility. You can help protect your account by:
- Using a strong, unique password
- Enabling multi-factor authentication
- Keeping your devices and software updated
- Being cautious of phishing attempts
- Not sharing your account credentials
- Logging out when using shared devices
- Reporting suspicious activity immediately
Responsible Disclosure
We welcome reports from security researchers who discover vulnerabilities. If you believe you've found a security issue:
- Email us at [email protected] with subject "Security Vulnerability"
- Provide detailed information about the vulnerability
- Give us reasonable time to address the issue before public disclosure
- Do not access or modify user data without permission
We appreciate responsible disclosure and will acknowledge your contribution.
Certifications and Compliance
We maintain compliance with industry standards and regulations:
- GDPR (General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
- PCI DSS (Payment Card Industry Data Security Standard) via Stripe
- SOC 2 Type II compliance (in progress)
Questions About Security
If you have questions about our security practices or want to report a security concern, please contact us:
Email: [email protected]
For security vulnerabilities, use subject line: "Security Vulnerability"