AIO Fusion handles real business and communications data on behalf of our clients, so security is built into the platform rather than added on afterwards. This page summarises the controls we currently have in place.
Encrypted connections
All traffic to and from AIO Fusion is served over HTTPS. Session cookies are marked HttpOnly and Secure, and use a SameSite policy, which protects your login session from common web-based attacks.
Access control
Access to client projects is scoped and enforced on our servers — not just hidden in the interface — so one client account cannot see another's data. Administrative actions are restricted to authorised roles.
No advertising trackers
We do not run advertising pixels or sell usage data. We use Google Analytics to understand how the Service is used and improve it. A strict content security policy limits what the app is allowed to load or connect to.
Backups
Client project data is backed up on a regular automated schedule, with integrity checks before each backup is retained.
Sub-processors
To generate audits and content, AIO Fusion sends the relevant project content to our AI providers (currently ChatGPT and Claude) for processing. We do not sell client data, and we do not use it to train third-party models beyond what is required to return a result to you.
Data minimisation
We only collect what is needed to run the platform: your account details (name, email) and the project, content and audit data you or your team enter. See our Privacy Policy for the full list.
AIO Fusion does not currently hold formal certifications such as SOC 2 or ISO 27001. As a growing platform, we've prioritised building strong technical controls first (see above) and will pursue formal certification as our customer base and compliance requirements grow. If your organisation requires a security questionnaire to be completed as part of procurement, get in touch and we're happy to work through it directly.
Ask us a security question