Security
Shelf data is commercial data. We treat it that way.
Aislix processes store photography, product distribution and share-of-shelf performance — information that reveals how a business trades. This page describes the controls that protect it and the practices behind our AI.
Encryption
All traffic is served over HTTPS with TLS 1.2+ and modern cipher suites. Shelf images, reports and database records are encrypted at rest with AES-256. Secrets and API keys are stored in a managed secret store, never in application code.
Secure storage
Every image and scan record is scoped to a single workspace and protected by row-level security policies enforced in the database, so one customer can never read another customer's data. Object storage buckets are private with short-lived signed URLs for downloads.
Authentication
Email and password sign-in with hashed credentials, session revocation from your profile, and role-based access for Owner, Admin, Manager and Viewer. Two-factor authentication and SSO are on the roadmap for Enterprise workspaces.
Data privacy
You own your shelf images and results. We never sell data, never share images between customers, and never use your images to train shared models. Deletion requests remove originals, annotations and reports from active storage immediately.
Responsible AI
Detections are returned with confidence scores so low-certainty results are visible rather than hidden. Models are evaluated on shelf diversity across categories and lighting conditions, and outputs are positioned as decision support that a human can verify.
Cloud infrastructure
Aislix runs on managed cloud infrastructure with isolated environments for development, preview and production. Deployments are automated and auditable, and production access requires multi-factor authentication and is logged.
Disaster recovery
Databases use point-in-time recovery with automated daily backups; object storage is replicated. Recovery procedures are documented with a target recovery point of 24 hours and a target recovery time of 4 hours.
Compliance
We align our controls with recognised industry practice, support GDPR-ready data-processing terms, and issue GST-compliant invoices for Indian businesses. Formal certification work is in progress and we will publish the status here as it completes.
Found a vulnerability?
Report it to hello@aislix.com with reproduction steps. We acknowledge reports within one business day, keep you updated, and will not pursue action against good-faith research.
