Home โบ Security
Trust & security
Security & data protection
AIP handles your stock, supplier and purchasing data, so we treat its security as core to the product. This page explains, in plain English, how we keep it safe and where it lives.
Last reviewed: 3 October 2026
Where your data lives
The AIP application and its database are hosted on Google Cloud in the EU (europe-west1, Belgium). Your account, stock, supplier and purchasing data is stored in the EU, giving you Irish and EU data residency by default. AIP is built and operated in Ireland.
Encryption
- In transit โ all traffic to and from AIP is encrypted with TLS/HTTPS. There are no unencrypted endpoints.
- At rest โ data stored in the database and in backups is encrypted at rest.
Per-tenant data isolation
Each customer is a separate tenant. Your data is logically separated from every other customer's and is only ever served back to your own account โ one client's stock, suppliers or pricing is never shown or cross-served to another.
Access control
- Access to systems and production data follows the principle of least privilege โ people and services get only the access they need.
- Secrets, API keys and credentials are stored server-side and are never exposed in the browser or shipped to the client.
- Administrative access to production is limited and controlled.
Backups & resilience
- Automated daily backups of the database, stored off-site and encrypted.
- Backups are retained for 90 days, so we can recover from data loss or corruption.
- 24/7 uptime monitoring so we're alerted to problems quickly.
You stay in control of buying
AIP works on the buyer's behalf, but no order is ever placed without the buyer's sign-off (autopilot is opt-in and bounded by limits you set). AIP never moves money โ you pay your suppliers directly. Your supplier and pricing data stays yours; we never sell it or share it with other customers or third parties for their own purposes.
Sub-processors
We use a small set of trusted providers who process data on our behalf. These are the same sub-processors listed in our Privacy Policy:
| Sub-processor | Purpose |
|---|---|
| Google Cloud | Hosting of the AIP application and database, in the EU (europe-west1, Belgium). |
| Google (Gemini API) | Powers the "source a part" web search. Only the product description you search for is sent โ never your account, contact or supplier data. |
| Google Workspace / Gmail | Delivering and handling order and enquiry email. |
Business customers can request our current sub-processor list at any time.
GDPR & data processing
AIP is GDPR-aligned and keeps your core application data in the EU. A Data Processing Agreement (DPA) is available to business customers on request. For how we handle personal data and your rights, see our Privacy Policy.
Certifications & roadmap
We build to recognised security practices and are working towards ISO 27001 and SOC 2. We do not currently hold these certifications โ we'll update this page as that work progresses, and we won't claim a certification we don't hold.
Responsible disclosure
If you believe you've found a security vulnerability in AIP, please tell us so we can fix it. Email contact@aiprocurement.ie with the details and we'll respond. Please give us a reasonable chance to address the issue before any public disclosure.
Questions about security?
Talk to us about data residency, a DPA, or your due-diligence checklist โ or start a free trial and see AIP with your own data.
This page describes our security practices in plain English and is not a contractual commitment or legal advice; it may change as the product evolves. For the legal terms of using AIP, see our Terms of Service.