AIFog reads your billing and resource data and, when you approve it, changes your cloud. That is a responsibility, not a feature. This page is the account of how we carry it: our ISO/IEC 27001:2022 certification, the controls behind it, what data we hold, where, and who else touches it.
We list only what is true today. A framework we map to is not a certificate we hold, and we label the difference.
AIFog operates a certified Information Security Management System. The scope covers the AIFog platform, the Azure infrastructure it runs on, the customer cloud billing and resource-configuration data it processes, and the people and processes that operate it.
Every SOC 2 criterion is mapped to an operating control in our ISMS, and the same evidence base serves both frameworks. A SOC 2 report is an opinion from a licensed CPA firm; we will list it here the day it is issued, not before.
Customer data is processed and stored in Azure Central India. We act as a processor for the billing and configuration data you connect; data-subject and deletion requests are handled through your organisation admin or by contacting us.
Each of these operates in production and is evidenced in the ISMS. Several are verified by the platform's own Prevent gate, the same engine we sell.
SSO through any OIDC or SAML identity provider with enforced MFA; local passwords are off in production. Seven scoped roles with separation of duties: author ≠ approver is enforced in code.
Row-level security is enforced on every tenant table (74+, forced, no owner bypass) and the application connects as a non-privileged role. One tenant cannot reach another's data even through a bug.
TLS 1.2/1.3 in transit. Cloud credentials are AES-256 encrypted at rest with keys held in a key vault; API keys are stored only as SHA-256 hashes.
No public data plane. Database, AI, storage and logs sit behind private endpoints; database administration runs through a locked-down jumpbox that is powered off when not in use.
Every privileged action lands in a hash-chained ledger (each entry sealed with the previous hash), with control identifiers for ISO 27001, SOC 2 and NIST so an export answers an auditor's question directly.
Agent actions go through ITIL-style change control: proposed, policy-gated, human-approved with typed confirmation, executed with a rollback hint, then verified against the bill.
Dependency CVE scanning and the Prevent gate run in CI and block the build; a CycloneDX SBOM ships with every release. Infrastructure changes are reviewed and tagged to an owner.
Documented business-continuity and disaster-recovery plan; restore drills are performed against real backups and the outcome is recorded as evidence.
You connect AWS, Azure or GCP with a reader role. Billing exports, resource configuration and utilization metrics are ingested; nothing is written back.
Recommendations and remediations are drafted with a justification dossier and scored by the Prevent gate. Nothing executes from a scan.
Write access is enabled per organisation. An approver confirms each action explicitly; execution records outcome and rollback, and savings are measured against the bill.
We do not ingest application data, workload contents, database rows, object storage contents or secrets from your environment.
| Subprocessor | Purpose | Location | Data |
|---|---|---|---|
| Microsoft Azure | Hosting: compute, database, storage, key vault, logging | Central India | All customer data, encrypted at rest |
| Azure OpenAI Service | Copilot and recommendation explanations | Central India (private endpoint) | Prompts built from your cost and configuration data; no training |
| Cloudflare | Edge delivery and access gateway for the application | Global edge | Request metadata, session tokens; no stored customer data |
| Resend | Transactional email (approvals, alerts, verification) | United States | Recipient email address and notification content |
We notify customers before adding a subprocessor that will handle customer data.
Send a note to it@aifog.ai from your company address. Certificates and reports are shared under NDA.
Report vulnerabilities to it@aifog.ai with "Security" in the subject. We acknowledge within two business days, keep you informed while we fix it, and will not pursue researchers who act in good faith and give us reasonable time to respond.