AI-IT INC · Affiliate-IT
Trust Center
Security, privacy, and compliance transparency for the Affiliate-IT platform.
SOC 2 Type II roadmap
Affiliate-IT is pursuing a SOC 2 Type II examination covering Security and Privacy trust service criteria. We maintain automated and organizational controls aligned with those criteria, including access management, content security, monitoring, data retention, and vendor oversight. An executive summary will be published here when our formal Type II attestation is available.
- Layered application security and authenticated access to customer data
- Health monitoring and operational status reporting
- Documented incident response and privacy practices
- Regular review of subprocessors and platform dependencies
Security program
We design the platform with defense in depth: encrypted transport, role-based access, tenant isolation for customer content, and retention policies for operational data. Vulnerability reports are reviewed promptly through the contact below.
Subprocessor registry
These vendors process customer data on our behalf. DPAs and security reviews are tracked internally (see also Privacy Policy).
| Vendor | Purpose |
|---|---|
| Vercel | Hosting, deployment, edge functions |
| Supabase | Database, authentication, storage |
| Stripe | Payments and billing (PCI scope delegated) |
| Together AI | Platform AI inference (when Platform key used) |
| OpenAI / Vercel AI Gateway | Optional AI providers (customer BYOK) |
| ElevenLabs | Voice / conversational AI features |
| Google Analytics | Analytics (consent-gated) |
Incident disclosure
We investigate security incidents per our incident response plan. Customers affected by a confirmed breach involving personal data will be notified without undue delay and in accordance with applicable law. Report vulnerabilities to admin@affiliate-it.com (see also security.txt). Operational status updates are posted on our system status page.