Skip to content
TTrust center

The platform we trust to run our own incidents.

AirTee.ai runs its own resilience programme inside AirTee.ai. Here's the posture, the sub-processors, and the documents you need for procurement.

01Certifications & alignment

Where we stand today.

01
UK & EU GDPR

Processor under a DPA; UK Addendum to the EU SCCs; data-subject rights supported in-product.

02
SOC 2

Control library built and mapped to the Trust Services Criteria; auditor engagement not yet started.

03
ISO 27001

Planned.

04
DORA / NIS2

Framework catalogues, notification clocks and attestation items support your own DORA and NIS2 obligations.

05
Dedicated environments

Single-tenant deployments in a UK, EU or US region on the Enterprise plan.

02Encryption & access controls

Engineering controls, in plain English.

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256, Google-managed keys).
  • Google and email sign-in; TOTP and SMS multi-factor authentication, enforceable per role by your admins; SAML/OIDC single sign-on on the Enterprise roadmap.
  • SCIM 2.0 provisioning for Okta and Microsoft Entra ID.
  • Role-based access with custom roles and 16 granular permissions, enforced at the data layer.
  • Tenant isolation: every record is scoped to your organisation at the API and database-rules layers.
03Audit & incident response

How we operate.

  • Point-in-time recovery plus daily backups; restore procedure drilled and timed.
  • Automated dependency, vulnerability and secret scanning on every change; independent penetration test scoped for 2026.
  • Documented incident response process with a published breach-notification commitment.
  • Responsible disclosure: hello@airtee.ai.
  • Sub-processor list is maintained in our privacy policy and updated at least 30 days before changes.
  • Security questionnaire, DPA and architecture overview available on request: security@airtee.ai.
04This website

Site security & privacy.

How airtee.ai itself is hardened, what we collect, and how cookies and analytics work — all on a dedicated page so you can audit it without scrolling. Read the site security & privacy page →

— next step

Need our DPA or sub-processor list?

Email security@airtee.ai or use the contact form. Most procurement requests turn around in 24 hours.