Trust
Security
How AIONIQ approaches the protection of information, systems, accounts and client work.
Security Overview
AIONIQ Labs treats client and account information as operationally sensitive. We use access control, encrypted transport, and limited third-party processors. We do not claim formal certifications on this page.
Controlled access to Workspace and studio systems.
Personal and project information handled with least-necessary sharing.
Hosted infrastructure with managed updates from our operators.
A path to report a security issue to the studio.
Infrastructure
The public website is hosted on Vercel. Workspace data that we persist lives in Supabase Postgres. Optional rate limiting may use Upstash Redis. Email is sent through Resend. Those operators maintain their own infrastructure security.
Access Control
Workspace access is invitation-based. Authentication uses platform passkeys rather than stored account passwords. Administrative and enrolment actions are logged.
Account Security
Session cookies are HttpOnly. Recovery material is stored as hashes, not as reusable secrets in the clear. Users can remove passkeys and anonymise account data from Workspace settings.
Data Protection
Traffic to the site is served over HTTPS. Personal data in forms is sent to our team over Resend. We do not publish a complete inventory of every internal tool on this page. See the Privacy Policy for what the website collects.
Client Project Access
Client project materials are shared with the people working on that engagement. Access is not offered as an open public download. Confidentiality expectations for a given project are set in the engagement documents.
Backups & Recovery
Hosted databases and deployments rely on the backup and recovery features of our infrastructure providers. We do not publish recovery-time commitments on this page.
Third-Party Services
Security of Vercel, Supabase, Resend and Upstash is documented by those companies. AIONIQ’s responsibility is to configure and use them in line with this page and the Privacy Policy.
Incident Response
If we become aware of a security incident that affects personal data we hold, we will investigate, contain what we can, and contact affected people or clients when we are required or it is appropriate to do so.
Responsible Disclosure
If you believe you have found a vulnerability in aioniq.com or Workspace, email talk@aioniqlabs.com with enough detail for us to reproduce it. Please do not access other people’s data or disrupt the service while reporting.
Security Contact
- talk@aioniqlabs.com
- AIONIQ Labs
- Ahmedabad, Gujarat, India
Questions about this document?