Security

Last Updated: January 2025

Our Commitment to Security

At AIM, security is not an afterthought. It's built into everything we do. We understand that you trust us with your personal information, task data, and financial commitments. We take this responsibility seriously and have implemented comprehensive security measures to protect your data.

Data Encryption

Encryption in Transit

All data transmitted between your device and our servers is encrypted using industry-standard TLS 1.3 (Transport Layer Security):

  • HTTPS protocol for all web communications
  • Certificate pinning for mobile applications
  • Secure WebSocket connections for real-time features
  • End-to-end encryption for sensitive operations

Encryption at Rest

Your data is encrypted when stored on our servers:

  • AES-256 encryption for all stored data
  • Encrypted database backups
  • Encrypted file storage
  • Secure key management using industry best practices

Authentication and Access Control

User Authentication

  • Secure password hashing using bcrypt
  • Multi-factor authentication (MFA) support
  • OAuth 2.0 integration for social login
  • Session management with secure tokens
  • Automatic session expiration
  • Account lockout after failed login attempts

Internal Access Controls

  • Role-based access control (RBAC) for employees
  • Principle of least privilege
  • Multi-factor authentication required for all staff
  • Comprehensive audit logging of access
  • Regular access reviews

Infrastructure Security

Cloud Infrastructure

We leverage Google Cloud Platform and Firebase, which provide:

  • SOC 2 Type II certified infrastructure
  • ISO 27001 certified data centers
  • Physical security with 24/7 monitoring
  • DDoS protection and mitigation
  • Automatic failover and redundancy
  • Geographic data replication

Network Security

  • Firewalls and intrusion detection systems
  • Network segmentation
  • Virtual Private Cloud (VPC) isolation
  • Regular network security assessments

Application Security

Secure Development Practices

  • Security by design principles
  • Regular code reviews focusing on security
  • Automated security scanning in CI/CD pipeline
  • Dependency vulnerability scanning
  • OWASP Top 10 compliance

Input Validation and Sanitization

  • Server-side validation of all inputs
  • Protection against SQL injection
  • Cross-Site Scripting (XSS) prevention
  • Cross-Site Request Forgery (CSRF) protection
  • Rate limiting to prevent abuse

Payment Security

Financial transactions are handled with the highest security standards:

  • PCI DSS compliant payment processing through Stripe
  • We never store credit card numbers on our servers
  • Tokenization of payment information
  • 3D Secure authentication for card payments
  • Fraud detection and prevention systems
  • Secure webhooks for payment notifications

Monitoring and Incident Response

24/7 Monitoring

  • Real-time security monitoring and alerting
  • Automated threat detection
  • Log aggregation and analysis
  • Anomaly detection systems
  • Uptime monitoring and health checks

Incident Response

We have a comprehensive incident response plan:

  • Dedicated security incident response team
  • Documented procedures for various incident types
  • Rapid response and containment protocols
  • Post-incident analysis and improvements
  • User notification in case of data breaches (as required by law)

Data Backup and Recovery

  • Automated daily backups of all data
  • Encrypted backup storage
  • Geographic backup redundancy
  • Regular backup restoration testing
  • Point-in-time recovery capabilities
  • Disaster recovery plan with defined RPO and RTO

Security Assessments

We regularly evaluate and improve our security posture:

  • Annual third-party security audits
  • Penetration testing by security professionals
  • Vulnerability assessments
  • Security code reviews
  • Compliance assessments (GDPR, SOC 2, etc.)

Employee Security

  • Background checks for all employees
  • Security awareness training
  • Confidentiality agreements
  • Secure device management policies
  • Regular security updates and training

Your Role in Security

Security is a shared responsibility. You can help protect your account by:

  • Using a strong, unique password
  • Enabling multi-factor authentication
  • Keeping your devices and software updated
  • Being cautious of phishing attempts
  • Not sharing your account credentials
  • Logging out when using shared devices
  • Reporting suspicious activity immediately

Responsible Disclosure

We welcome reports from security researchers who discover vulnerabilities. If you believe you've found a security issue:

  • Email us at [email protected] with subject "Security Vulnerability"
  • Provide detailed information about the vulnerability
  • Give us reasonable time to address the issue before public disclosure
  • Do not access or modify user data without permission

We appreciate responsible disclosure and will acknowledge your contribution.

Certifications and Compliance

We maintain compliance with industry standards and regulations:

  • GDPR (General Data Protection Regulation)
  • CCPA (California Consumer Privacy Act)
  • PCI DSS (Payment Card Industry Data Security Standard) via Stripe
  • SOC 2 Type II compliance (in progress)

Questions About Security

If you have questions about our security practices or want to report a security concern, please contact us:

Email: [email protected]

For security vulnerabilities, use subject line: "Security Vulnerability"