AIBODY Trust Center

Security, compliance, controls, and transparency—everything you need to trust how we protect your data.
digital twin copy

Compliance & Resources

cyber-essentials-logo
Demonstrates our commitment to baseline security controls through an annual Cyber Essentials assessment of key systems and practices.

Disclaimer: Cyber Essentials is completed as an assessment; it should not be interpreted as a formal certification unless explicitly stated.
Download Certificate
ISO-27001-logo
Highlights alignment with an ISO/IEC 27001:2022 certified information security management system through our key service partner.

Disclaimer: The ISO/IEC 27001:2022 certificate is held by Onseo Affiliates; it applies to their ISMS scope, not as a direct AIBODY certification.
Download Certificate

Controls

Our security controls outline how we protect data across infrastructure, organization, product, and privacy—along with each control’s implementation status.
Infrastructure Security
Organizational Security
Product Security
Internal Security Procedures
Data and Privacy
Restricted access to production databases
Access to production databases is limited to authorized personnel with a verified business need and appropriate privileges.

Restricted access to production networks
Privileged access to production networks is granted only to authorized users based on role and business necessity.

Unique authentication enforced
Access to production systems requires unique user authentication, using individual usernames and passwords or approved Secure Shell (SSH) keys.

Encrypted remote access
Remote access to production systems is permitted only through approved, encrypted connections and is restricted to authorized employees.

Log management and monitoring
The company employs centralized log management to detect, analyze, and respond to events that could impact security objectives.

Network segmentation
The production environment is segmented to minimize risk and prevent unauthorized access to customer data.
Employee background checks
Background checks are conducted for all new employees in accordance with applicable laws and regulations.

Contractor confidentiality agreements
All contractors are required to sign a confidentiality agreement prior to engagement.

Employee confidentiality agreements
Employees acknowledge and sign NDA as part of the onboarding process.

Performance evaluations
Managers conduct performance evaluations for their direct reports at least once a year.
Encryption at rest
Sensitive customer data stored in company-managed data storage is encrypted at rest.

Control self-assessments
The company performs control self-assessments at least once a year to confirm that security controls are properly designed and operating effectively.

Encryption in transit
Secure transmission protocols are used to encrypt confidential and sensitive data transmitted over public networks.

Vulnerability and system monitoring
The policies define requirements for vulnerability management and continuous system monitoring within IT and Engineering functions.
Configuration management
A configuration management process ensures systems are deployed and maintained in a consistent and secure manner.

Documented organizational structure
The company maintains an up-to-date organizational chart outlining reporting lines and responsibilities.

Defined roles and responsibilities
Information security roles and responsibilities across system design, development, operation, and monitoring are formally documented.

Support and incident reporting
A support system enables users to report incidents, failures, concerns, and other issues to appropriate personnel.

Access provisioning controls
User access to system components is role-based and requires documented approval prior to provisioning.

Customer support resources
Guidelines and technical support resources related to system operations are available to customers.

Service transparency
The company provides clear descriptions of its products and services to both internal and external users.

Risk management objectives
Risk management objectives are defined to support the identification and assessment of risks affecting service commitments.

Risk assessments
Risk assessments are conducted at least once a year, considering environmental, regulatory, technological changes, and potential fraud risks.

Third-party management
Written agreements with vendors and third parties include confidentiality and privacy obligations appropriate to the services provided.
AI and Customer Data

We do not use customer data to train our AI models. Your data is used only to provide and support our services — never for advertising, resale, or unrelated product development.

Customer data deletion
Upon service termination, customer data containing confidential information is securely deleted or purged from the application environment in accordance with best practices.

FAQs

Find clear, straightforward answers about how we protect data, manage access, work with subprocessors, and meet security expectations.
Data Usage & Residency
Security Standards & Compliance

Does AIBODY sell or share user data with third parties?

AIBODY does not sell your personal data. For details on data sharing practices, please refer to Privacy Policy: https://aibody.io/privacy-policy/


Where is the data stored?

Data storage location: Amazon Web Services servers located in London 


Who are AIBODY's sub-processors? 

A list if our sub-processors is publicly available at https://trust.aibody.io/subprocessors 

 

What security certifications does AIBODY hold? 

AIBODY performs a regular (annual) Cyber Essential assessment. 
Our key subcontractor - Onseo Affiliates, holds ISO/IEC 27001:2022 (Information Security Management System) compliance certificate. 

Issued certificates you could find on https://trust.aibody.io/resources 

  

What security measures does Manus implement? 

Encryption: Data encrypted in transit (TLS) and at rest (AES-256) 

Access Controls: Role-based permissions, MFA required for administrators 
Data Isolation: separate account per user 
Monitoring: Continuous security monitoring, regular vulnerability assessments 

Subprocessors

See the trusted third-party service providers we use to operate AIBODY, what they do, and how they may process limited customer data.

* Our key partner, Onseo Affiliates, is an ISO 27001-certified company. Also, our ISMS largely conforms to Onseo's. 
Anthropic-Icon--Streamline-Svg-Logos

Anthropic 

Foundational models 
Google Cloud Platform 

Google Cloud Platform 

Cloud infrastructure and foundational models 
Microsoft Azure AI Foundry 

Microsoft Azure AI Foundry 

Cloud infrastructure 
Amazon Web Services 

Amazon Web Services 

Cloud infrastructure
Onseo Affiliates Limited

Onseo Affiliates Limited

Employees accounting, development resources facilitation  

Book a Demo

Book a live demo and explore how our real-time simulations can transform your clinical training or research.