The short version
- You own your project data and the outputs generated from it (Terms, §3).
- No model training on your data. AIM Works doesn't train or fine-tune any model on your inputs, prompts, or outputs, and Anthropic doesn't train on data sent through our commercial API account.
- Projects are private to your account unless you share one by email.
- Encrypted in transit (HTTPS/TLS) and at rest (managed by our database provider).
- Not SOC 2 certified. No SOC 2 audit is under way.
Who processes your data
| Provider | What it does | What it may process |
|---|---|---|
| Supabase | Authentication and the primary database (PostgreSQL, United States) | Account email, hashed password, subscription state, saved projects |
| Railway | Runs the AIM Works application (United States) | Requests and responses passing through the running app. No separate customer datastore. |
| Anthropic | The AI provider (Claude) for the co-pilot and AI-assisted steps | The project context and text you send to an AI feature |
| Stripe | Subscription billing | Billing email and subscription state. Card data is entered directly into Stripe; AIM Works never stores full card numbers. |
| Sentry | Error monitoring, when enabled | Error traces and context, configured not to send IP addresses by default |
The Privacy Policy has the full list and terms.
AI and your project
When you use the co-pilot or another AI feature, the relevant project context, such as zones, loads, and your question, is sent to Anthropic's API over TLS to generate the response. Under Anthropic's commercial API terms, that data isn't used for training and is retained only for a limited period for security and abuse prevention. AIM Works doesn't use your project data to train any model.
The AI cannot change your project on its own. Every edit it proposes waits as a Pending Change until you accept it. Calculations run in deterministic engines and never depend on the AI.
Don't send the AI anything your client contracts prohibit sharing with a US-based AI provider. Calculations that don't call the AI are never sent to Anthropic.
Access to projects
Each saved project belongs to the account that created it. PostgreSQL row-level security limits a project to its owner and to the people the owner has explicitly shared it with by email. Every server-side query also filters by owner, so isolation doesn't rest on a single mechanism.
Operator access. AIM Works is a founder-led team. The application server uses a privileged database connection to run the service. A written staff-access policy and an audit log of administrative access are not yet in place. If a client contract requires specific access commitments, ask us before you upload.
Uploaded drawings
When you import rooms from a PDF floor plan, the file is held in your working session to extract rooms and zones. What's saved to your project is the extracted rooms and geometry, not the PDF itself. If you choose an AI-assisted step on a drawing, the page content needed for that step is sent to Anthropic for that request.
Deletion, retention, and backups
- Delete a project: removing it from the Projects page deletes it from the database.
- Close your account: account and project data are deleted from active systems within about 30 days.
- Backups: database backups are managed by Supabase. Deleted data ages out of backups on the provider's cycle, generally within about 30 days.
- Cancelling a subscription doesn't delete your projects. You can still export them.
- Local copies: you can download any project as a backup file at any time.
Retention targets are in the Privacy Policy. Formal deletion SLAs and a signed DPA are not yet available as standard. Ask us if you need one.
Not in place yet
These are the gaps a security review will ask about. We'd rather you hear them from us.
| Control | Status |
|---|---|
| SOC 2 (Type I or II) | Not certified; no audit under way |
| Independent penetration test | Not yet performed |
| Single sign-on (SAML / OIDC) and SCIM | Not available |
| Multi-factor authentication | Not yet enforced in the app |
| Organization accounts and role-based access | Not available; accounts are individual, with owner-controlled sharing |
| Audit log of user and administrative actions | Not in place |
| Formal RTO / RPO commitments | Not defined; relies on the provider's managed backups |
Questions or a security review
Email support@getaimworks.com for a security questionnaire, a DPA, or anything not covered here.