Security at every layer
AYAN processes brand and perception data for global organisations. This page is the technical answer to the questions your IT and security teams ask before onboarding a vendor, controls, data flows, sub-processors, and how to reach us.
- Hosting region
- EU / UAE
- Encryption
- AES-256 at rest · TLS 1.3 in transit
- Customer data used for AI training
- Never
- Security response SLA
- 1 business day
Data encryption
All customer data is encrypted in transit (TLS 1.3, modern cipher suites only) and at rest (AES-256-GCM). This covers the primary database, object storage, and every backup. Keys are managed by the hosting provider’s KMS with envelope encryption scoped per tenant.
Tenant isolation
Each organisation’s data is logically isolated, with row-level access controls and per-organisation API keys. Every access to production data is logged immutably and reviewed. There are no shared admin credentials.
No model training on your data
Your brand, prompts, and audit inputs are never used to train AI models, ours or any third party’s. LLM providers we route inference to operate under their enterprise no-train terms. Model outputs are kept under your account, not shared back to providers.
Infrastructure
Production runs on managed services in EU and UAE regions, fronted by an edge network with DDoS protection and a web application firewall. Application, data, and admin planes are network-segmented. No public database endpoints.
- SOC 2· Controls aligned with Type II, formal audit on roadmap
Internal controls follow the SOC 2 Trust Services Criteria for security and availability. A third-party Type II audit is on the roadmap.
- ISO 27001· Planned
Information security management framework being formalised against ISO/IEC 27001:2022.
- GDPR· Aligned by design
Lawful basis, Data Processing Agreement, Standard Contractual Clauses and data-subject request workflow in place. See /privacy.
- UAE PDPL· Aligned by design
Obligations under Federal Decree-Law No. 45 of 2021 met as a UAE-domiciled controller and processor.
1. Overview & shared-responsibility model
AYAN LABS FRONTIER SOFTWARE - FZCO (“AYAN”) is a Dubai-domiciled company building the AYAN platform for AI Brand Intelligence. We process brand assets, prompts, perception telemetry, and the audit outputs derived from them on behalf of our customers. This document describes the security controls AYAN is responsible for, and the controls our customers retain.
AYAN is responsible for:
- Physical and platform security of the hosting environment.
- Encryption of data in transit and at rest.
- Application security, secure SDLC, and vulnerability management.
- Logging, monitoring, and incident response on the platform.
- Vendor and sub-processor due diligence.
The customer is responsible for:
- User lifecycle on their side (joiners, movers, leavers, SSO configuration).
- Custody of API keys issued to their organisation.
- Classification of the data they upload and the lawful basis for processing it.
- Configuring per-organisation settings (model allowlists, retention, integrations).
2. Data flow & residency
Customer data travels through a small, well-defined pipeline. Inbound: HTTPS upload to the application API. Storage: a managed Postgres database in an EU region, with encrypted object storage for media and document artefacts. Processing: ephemeral workers handle LLM inference calls and write structured outputs back to the database. Audit: every read and mutation against customer data is recorded in a tamper-evident log.
Production data is stored in the EU. LLM inference may route to providers in the EU or US, depending on the model the customer has selected. Customers can configure a per-organisation regional allowlist that restricts inference to specific provider regions.
Cross-border transfers rely on the European Commission’s Standard Contractual Clauses, the UK addendum where applicable, and the UAE PDPL transfer mechanisms for the reverse leg. Sub-processors with US data flows operate under the relevant data-transfer frameworks.
3. Encryption & key management
Controls in summary:
- TLS 1.3 for all in-transit traffic, with HSTS preloaded on the public marketing surface.
- AES-256-GCM for data at rest, database, backups, object storage.
- Envelope encryption: tenant-scoped data encryption keys (DEKs) wrapped by key-encryption keys (KEKs) held in the hosting provider’s KMS.
- Key rotation: KEKs rotated annually; DEK rotation on demand and on tenant offboarding.
- No customer-managed keys today. Bring-your-own-key (BYOK) is on the 12-month roadmap.
4. Identity, access control & SSO
Workforce access:
- Single sign-on with hardware-key two-factor authentication enforced for all engineering and admin roles.
- Production access is role-based and time-boxed: privileged operations require just-in-time elevation and are logged immutably.
- Principle of least privilege applied at every layer. Quarterly access review.
Customer-side access:
- SAML / OIDC SSO available on enterprise tier.
- Per-organisation API keys with scoped permissions and rotation support.
- Audit log of administrative actions exported on request.
5. AI/LLM data handling
AYAN is built around LLM inference. The way we handle the data sent to and from those models is the single most important control on this page.
- Customer brand data is never used to train AYAN models or any third-party model.
- All LLM providers we route inference to operate under their enterprise no-train terms.
- Prompt and response payloads are encrypted in transit and stored only within the customer’s tenant in our database.
- Where feasible, personally identifying fields are redacted or referenced by stable handle before being sent to a provider.
- Customers can configure a per-organisation model allowlist (which providers and regions are eligible).
- Provider-side retention is configured to the shortest available window. We can supply each provider’s data-processing addendum on request.
6. Application security & SDLC
Every change to production goes through a documented secure development lifecycle:
- Pull-request review by at least one engineer who did not author the change.
- Automated CI: linting, type-checking, unit and integration tests on every PR.
- Static analysis (security-focused lint rules, semgrep) and dependency scanning on every PR.
- Secrets never live in source, they are held in the hosting provider’s secret manager and injected at runtime.
- Branch protection on the main branch. Force-pushes are blocked. Releases are tagged and signed.
7. Infrastructure & hosting
Production runs on managed services from SOC 2 Type II-certified providers, in EU and UAE regions. Specific provider names are listed in the sub-processors table below or available on request.
- Edge network and web application firewall in front of every public endpoint.
- Application, data, and administrative planes are segmented; the database has no public endpoint.
- Hardened container images, immutable infrastructure, infrastructure-as-code for every production change.
- Secrets and configuration managed through the provider’s vault, no shared service accounts.
8. Logging, monitoring & detection
Application logs and audit trails are centralised in a tamper-evident store with twelve-month retention. Security-relevant events, failed admin logins, scoped-token misuse, anomalous egress, configuration changes on production, trigger alerts routed to on-call. Detection coverage is reviewed quarterly against the OWASP Top 10 and the MITRE ATT&CK techniques most relevant to SaaS platforms.
9. Vulnerability management & testing
Our vulnerability management programme runs continuously:
- Dependency scanning on every push, with automated pull requests for known-vulnerable packages.
- SLA-driven patching: critical fixes within 72 hours, high within 7 days, medium within 30 days.
- Annual third-party penetration test once the platform reaches GA; an internal red-team rotation operates in the meantime.
- Bug-bounty and responsible-disclosure inbox at [email protected], see the contact section below.
10. Incident response & breach notification
AYAN maintains a documented incident-response runbook with a named on-call rotation and a severity matrix (Sev 1 through Sev 4). Targets:
- Sev 1: acknowledge within 30 minutes, customer-facing update within 2 hours.
- Sev 2: acknowledge within 2 business hours.
- Sev 3–4: acknowledge within 1 business day.
For incidents confirmed to affect customer data, AYAN notifies the affected customer within 72 hours of confirmation, with a timeline, scope, and remediation plan, in line with GDPR Article 33 and the UAE PDPL. A written post-mortem is shared with the affected customer once the incident is closed.
11. Business continuity & disaster recovery
Customer data is protected by layered backups and a tested recovery plan:
- Database point-in-time recovery plus daily encrypted snapshots.
- Object storage is versioned, with cross-region replication for critical objects.
- Target Recovery Point Objective (RPO): 24 hours. Target Recovery Time Objective (RTO): 8 hours for the production environment.
- Backups are tested through restore drills at least annually. Disaster-recovery drills are run at least annually.
- Vendor concentration risk is reviewed at each architecture milestone.
12. Sub-processors & vendor risk
Every sub-processor goes through a documented assessment that captures their security posture, certifications, location, and the data-processing agreement we hold with them. Material additions or changes to our sub-processors are announced at least thirty days before they go live, via the customer-admin email channel. The categories of sub-processor currently in use are listed in the sub-processors table on this page; a current, named list with regions and DPAs is available on request at [email protected].
13. Privacy & data-subject rights
Detailed privacy commitments are in the Privacy Policy at /privacy. AYAN provides a pre-signed Data Processing Agreement on request and can execute the customer’s DPA where the substantive terms match. Data-subject requests (access, rectification, erasure, portability, restriction, objection) are routed via [email protected] and are handled within the timelines required by GDPR and the UAE PDPL.
14. Employee security & responsible disclosure
People controls:
- Background checks where lawful in the employee’s jurisdiction.
- Mandatory security training at onboarding and annual refresher.
- Signed confidentiality and acceptable-use agreements.
- Endpoint management with full-disk encryption, screen-lock enforcement, and EDR.
- SSO with mandatory two-factor authentication enforced on workforce identities.
- Offboarding revokes access within one business day.
Responsible disclosure:
- Reach [email protected] to report a vulnerability.
- We acknowledge reports within one business day.
- Safe harbor for good-faith security research within scope: we will not pursue legal action against researchers acting in good faith and within the disclosure policy.
Sub-processors
Categories of third parties that process customer data on our behalf. A current, named list with regions and DPAs is available on request at [email protected]. Customers are notified at least thirty days before any material change.
- Managed cloud hostingEU
Application compute, managed database, encrypted object storage
- Edge network & WAFGlobal edge
DNS, DDoS protection, application firewall, CDN
- LLM providersEU / US
Inference for Perception Scans (enterprise no-train terms)
- Transactional emailEU / US
Account, support, and notification email delivery
- Marketing analyticsUS
Aggregated visitor analytics on the marketing website
Security artefacts
Documents your IT, procurement, and legal teams can request. Items marked "On request" are released under mutual NDA.
- Request →Security whitepaperOn request
Overview of architecture, controls, and certifications.
- Request →Data Processing Agreement (DPA)On request
Pre-signed template aligned with GDPR Article 28 and UAE PDPL.
- Request →Sub-processors list (named)On request
Current, named list of sub-processors with regions and DPAs.
- Request →SOC 2 Type II reportOn request
Released under mutual NDA when the audit completes.
- Request →Penetration test summaryOn request
Latest external assessment summary, released under mutual NDA.
Contact & responsible disclosure
Report a vulnerability, request the DPA, or escalate a security incident. We aim to acknowledge within one business day.
- Security team
- [email protected]
- Legal & privacy
- [email protected]