Platform Prevent Autopilot Compliance Trust Compare About Request documents Get started →
Trust Center

Connected to your cloud. Held to a standard.

AIFog reads your billing and resource data and, when you approve it, changes your cloud. That is a responsibility, not a feature. This page is the account of how we carry it: our ISO/IEC 27001:2022 certification, the controls behind it, what data we hold, where, and who else touches it.

Certifications & attestations

What has been independently assessed, and what has not.

We list only what is true today. A framework we map to is not a certificate we hold, and we label the difference.

Certified

ISO/IEC 27001:2022

AIFog operates a certified Information Security Management System. The scope covers the AIFog platform, the Azure infrastructure it runs on, the customer cloud billing and resource-configuration data it processes, and the people and processes that operate it.

Standard
ISO/IEC 27001:2022 (93 Annex A controls, 2022 edition)
Certified
2026
Evidence
Certificate and Statement of Applicability available on request
Controls mapped

SOC 2 (Trust Services Criteria)

Every SOC 2 criterion is mapped to an operating control in our ISMS, and the same evidence base serves both frameworks. A SOC 2 report is an opinion from a licensed CPA firm; we will list it here the day it is issued, not before.

Status
Control mapping complete; audit not yet issued
Evidence
SOC 2 control mapping available on request
Designed for

GDPR & India DPDP

Customer data is processed and stored in Azure Central India. We act as a processor for the billing and configuration data you connect; data-subject and deletion requests are handled through your organisation admin or by contacting us.

Residency
Azure Central India (no cross-region replication of customer data)
Evidence
Data Processing Agreement on request
Security controls

The controls the certificate stands on.

Each of these operates in production and is evidenced in the ISMS. Several are verified by the platform's own Prevent gate, the same engine we sell.

Identity & access

SSO through any OIDC or SAML identity provider with enforced MFA; local passwords are off in production. Seven scoped roles with separation of duties: author ≠ approver is enforced in code.

Tenant isolation

Row-level security is enforced on every tenant table (74+, forced, no owner bypass) and the application connects as a non-privileged role. One tenant cannot reach another's data even through a bug.

Encryption

TLS 1.2/1.3 in transit. Cloud credentials are AES-256 encrypted at rest with keys held in a key vault; API keys are stored only as SHA-256 hashes.

Private by default

No public data plane. Database, AI, storage and logs sit behind private endpoints; database administration runs through a locked-down jumpbox that is powered off when not in use.

Tamper-evident audit

Every privileged action lands in a hash-chained ledger (each entry sealed with the previous hash), with control identifiers for ISO 27001, SOC 2 and NIST so an export answers an auditor's question directly.

Change control

Agent actions go through ITIL-style change control: proposed, policy-gated, human-approved with typed confirmation, executed with a rollback hint, then verified against the bill.

Secure development

Dependency CVE scanning and the Prevent gate run in CI and block the build; a CycloneDX SBOM ships with every release. Infrastructure changes are reviewed and tagged to an owner.

Resilience

Documented business-continuity and disaster-recovery plan; restore drills are performed against real backups and the outcome is recorded as evidence.

How we touch your cloud

Read-only until you decide otherwise.

01 · CONNECT

Least-privilege, read-only

You connect AWS, Azure or GCP with a reader role. Billing exports, resource configuration and utilization metrics are ingested; nothing is written back.

02 · PROPOSE

Every change is a proposal

Recommendations and remediations are drafted with a justification dossier and scored by the Prevent gate. Nothing executes from a scan.

03 · APPROVE & EXECUTE

Opt-in, human-approved, reversible where possible

Write access is enabled per organisation. An approver confirms each action explicitly; execution records outcome and rollback, and savings are measured against the bill.

Data

What we hold, where it lives, and who else sees it.

What we process

  • Cloud billing data — cost and usage exports (FOCUS format where available) from your providers.
  • Resource configuration — inventory, tags, SKUs, network exposure and identity posture needed to score cost and risk.
  • Utilization metrics — CPU, memory, storage and connection counts from the providers' monitoring APIs.
  • Account data — the names and email addresses of your users, their roles, and the audit trail of their actions.

We do not ingest application data, workload contents, database rows, object storage contents or secrets from your environment.

Where it lives, and for how long

  • Region: Azure Central India. No customer data is replicated outside the region.
  • Retention: for the life of your subscription; deleted within 30 days of termination on request.
  • AI processing: the Copilot runs on Azure OpenAI inside our private network, authenticated by managed identity. Your data is not used to train any model.
  • Backups: encrypted, in-region, restore-tested.
SubprocessorPurposeLocationData
Microsoft AzureHosting: compute, database, storage, key vault, loggingCentral IndiaAll customer data, encrypted at rest
Azure OpenAI ServiceCopilot and recommendation explanationsCentral India (private endpoint)Prompts built from your cost and configuration data; no training
CloudflareEdge delivery and access gateway for the applicationGlobal edgeRequest metadata, session tokens; no stored customer data
ResendTransactional email (approvals, alerts, verification)United StatesRecipient email address and notification content

We notify customers before adding a subprocessor that will handle customer data.

Documents

Available on request.

Send a note to it@aifog.ai from your company address. Certificates and reports are shared under NDA.

ISO/IEC 27001:2022 certificateScope statement included
Statement of Applicability93 Annex A controls
SOC 2 control mappingTrust Services Criteria
Information security policy setAccess control · cryptography · change management · incident response · BC/DR · vendor management · acceptable use · data classification
Data Processing AgreementGDPR / DPDP
Security questionnaire answersCAIQ / SIG-style, on request
Responsible disclosure

Found something? Tell us first.

Report vulnerabilities to it@aifog.ai with "Security" in the subject. We acknowledge within two business days, keep you informed while we fix it, and will not pursue researchers who act in good faith and give us reasonable time to respond.