generated: '2026-07-17' method: searched source: https://aito.ai/trust/security/ standards: - id: oauth2 conforms: false evidence: OpenAPI declares only an apiKey (x-api-key) security scheme; no oauth2 flows. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Error responses are plain JSON (400 "Invalid request body"), not application/problem+json. - id: rfc7231-http conforms: true evidence: REST/JSON over HTTPS; POST query operations under /api/v1. - id: gdpr conforms: true evidence: >- Aito operates as a GDPR Data Processor (customer is Data Controller); all infrastructure hosted in the EU (Ireland, eu-west-1) on AWS. Documented at https://aito.ai/trust/security/. - id: tls conforms: true evidence: All API communication uses TLS 1.2+ (probed hosts negotiate TLSv1.3). - id: soc2 conforms: false evidence: Aito states it does not currently hold SOC 2 certification. - id: iso27001 conforms: false evidence: Aito states it does not currently hold ISO 27001 certification.