Security & Project Data

How AIM Works handles your projects, written plainly. It lists what is in place today and what isn't yet. We don't claim controls we haven't built.

The short version

Who processes your data

ProviderWhat it doesWhat it may process
SupabaseAuthentication and the primary database (PostgreSQL, United States)Account email, hashed password, subscription state, saved projects
RailwayRuns the AIM Works application (United States)Requests and responses passing through the running app. No separate customer datastore.
AnthropicThe AI provider (Claude) for the co-pilot and AI-assisted stepsThe project context and text you send to an AI feature
StripeSubscription billingBilling email and subscription state. Card data is entered directly into Stripe; AIM Works never stores full card numbers.
SentryError monitoring, when enabledError traces and context, configured not to send IP addresses by default

The Privacy Policy has the full list and terms.

AI and your project

When you use the co-pilot or another AI feature, the relevant project context, such as zones, loads, and your question, is sent to Anthropic's API over TLS to generate the response. Under Anthropic's commercial API terms, that data isn't used for training and is retained only for a limited period for security and abuse prevention. AIM Works doesn't use your project data to train any model.

The AI cannot change your project on its own. Every edit it proposes waits as a Pending Change until you accept it. Calculations run in deterministic engines and never depend on the AI.

Don't send the AI anything your client contracts prohibit sharing with a US-based AI provider. Calculations that don't call the AI are never sent to Anthropic.

Access to projects

Each saved project belongs to the account that created it. PostgreSQL row-level security limits a project to its owner and to the people the owner has explicitly shared it with by email. Every server-side query also filters by owner, so isolation doesn't rest on a single mechanism.

Operator access. AIM Works is a founder-led team. The application server uses a privileged database connection to run the service. A written staff-access policy and an audit log of administrative access are not yet in place. If a client contract requires specific access commitments, ask us before you upload.

Uploaded drawings

When you import rooms from a PDF floor plan, the file is held in your working session to extract rooms and zones. What's saved to your project is the extracted rooms and geometry, not the PDF itself. If you choose an AI-assisted step on a drawing, the page content needed for that step is sent to Anthropic for that request.

Deletion, retention, and backups

Retention targets are in the Privacy Policy. Formal deletion SLAs and a signed DPA are not yet available as standard. Ask us if you need one.

Not in place yet

These are the gaps a security review will ask about. We'd rather you hear them from us.

ControlStatus
SOC 2 (Type I or II)Not certified; no audit under way
Independent penetration testNot yet performed
Single sign-on (SAML / OIDC) and SCIMNot available
Multi-factor authenticationNot yet enforced in the app
Organization accounts and role-based accessNot available; accounts are individual, with owner-controlled sharing
Audit log of user and administrative actionsNot in place
Formal RTO / RPO commitmentsNot defined; relies on the provider's managed backups

Questions or a security review

Email support@getaimworks.com for a security questionnaire, a DPA, or anything not covered here.

Walk through it with your own concerns in hand.

We'll show where data goes during a real project, step by step.

Book a Demo