Skip to main content

Trust

Security

How AIONIQ approaches the protection of information, systems, accounts and client work.

Studio
AIONIQ Labs
Last updated
Last updated 17 September 2026
01

Security Overview

AIONIQ Labs treats client and account information as operationally sensitive. We use access control, encrypted transport, and limited third-party processors. We do not claim formal certifications on this page.

Access

Controlled access to Workspace and studio systems.

Data

Personal and project information handled with least-necessary sharing.

Systems

Hosted infrastructure with managed updates from our operators.

Response

A path to report a security issue to the studio.

02

Infrastructure

The public website is hosted on Vercel. Workspace data that we persist lives in Supabase Postgres. Optional rate limiting may use Upstash Redis. Email is sent through Resend. Those operators maintain their own infrastructure security.

03

Access Control

Workspace access is invitation-based. Authentication uses platform passkeys rather than stored account passwords. Administrative and enrolment actions are logged.

04

Account Security

Session cookies are HttpOnly. Recovery material is stored as hashes, not as reusable secrets in the clear. Users can remove passkeys and anonymise account data from Workspace settings.

05

Data Protection

Traffic to the site is served over HTTPS. Personal data in forms is sent to our team over Resend. We do not publish a complete inventory of every internal tool on this page. See the Privacy Policy for what the website collects.

06

Client Project Access

Client project materials are shared with the people working on that engagement. Access is not offered as an open public download. Confidentiality expectations for a given project are set in the engagement documents.

07

Backups & Recovery

Hosted databases and deployments rely on the backup and recovery features of our infrastructure providers. We do not publish recovery-time commitments on this page.

08

Third-Party Services

Security of Vercel, Supabase, Resend and Upstash is documented by those companies. AIONIQ’s responsibility is to configure and use them in line with this page and the Privacy Policy.

09

Incident Response

If we become aware of a security incident that affects personal data we hold, we will investigate, contain what we can, and contact affected people or clients when we are required or it is appropriate to do so.

10

Responsible Disclosure

If you believe you have found a vulnerability in aioniq.com or Workspace, email talk@aioniqlabs.com with enough detail for us to reproduce it. Please do not access other people’s data or disrupt the service while reporting.

11

Security Contact

  • talk@aioniqlabs.com
  • AIONIQ Labs
  • Ahmedabad, Gujarat, India

Questions about this document?