Security · Trust & Platform
Control and protection are built in, not bolted on. Aitronos is one AI platform underneath the tools your company already runs, so who can reach what is set in one place — your organization settings — and every decision lands on the same record.
This page is both halves: the certificate, and the controls behind it — members, departments, roles, the record of every change, and what each person can reach.
Thirty minutes, on one process of your own. Nothing to install first.
The certificate
Certified means a certificate: ISO/IEC 27001:2022, number IC-IS-2606004, issued to Aitronos AG on 1 June 2026 by InterCert. What it attests is the management system — how security is actually run: risk, access, incidents, suppliers, change — examined by an external auditor against the standard.
It is not permanent, and that is its value: surveillance to 31 May 2027, recertification due 31 May 2029. It holds only as long as the audits keep passing.
The signed certificate is a document rather than a web page. Ask for it on the right, tell us who you are, and it downloads on the spot.
ISO/IEC 27001:2022
Certificate IC-IS-2606004
Validity
The signed certificate Exactly as InterCert issued it — PDF, 1.6 MB.
The controls
Access lives in your organization settings, and your own administrators run it. Seven screens sit behind that tab strip — who is in your company, where they sit, what they can open, what happened, what the defaults are, what runs without a person, and what any one person actually holds. Here are all seven.
| Name | Status | Role | Department | Joined | |
|---|---|---|---|---|---|
| A. Meier | Active | Member | Sales | 22 Jul 2026 | |
| R. Kaufmann | Active | Dept. Manager | Operations | 22 Jul 2026 | |
| T. Brunner | Active | Billing Manager | Finance | 23 Jul 2026 | |
| S. Frei | Deactivated | Member | IT | 14 Mar 2026 | |
| j.weber@ | Invited | Member | — | — | |
| M. Perren external | Active | Guest | — | 04 Aug 2026 |
1 selected — bulk actions: role, department, status, export
Expand all
9 members
Inherited from
Top-level department — no permissions are inherited.
Sub-departments · 3
Sharing scope
Department and private.
58 of 247 capabilities · 2 members
58 of 247 granted23%
8 areas not granted
| Date & time | Actor | Action | Entity |
|---|---|---|---|
| 12 Aug · 17:04 | P. Loacker p***@a***.com | Updated | Role · Knowledge Manager +2 capabilities |
| 12 Aug · 16:41 | A. Meier | Shared | Knowledge store · Pricing 2026 Sales · can view |
| 11 Aug · 09:12 | R. Kaufmann | Invited | User · j.weber@ Member · Sales |
| 10 Aug · 14:58 | T. Brunner | Removed | Department · Field service 3 members reassigned |
| 09 Aug · 08:20 | Ops assistant service account | Created | API key · Logistics sync expires 09 Nov 2026 |
Showing 1–25 of 134 entries123›
Permission preset
Controls the default permissions for the Member role. Custom roles are not affected.
Allowed email domains
Users with these domains can sign up and join without an invitation.
aitronos.comaitronos.ch + Add domainGuest access expiry
Two clocks, either or both. Signing in resets the first.
| Name | Type | Linked assistant | Status | API keys | Created |
|---|---|---|---|---|---|
| Logistics sync | Bot | — | Active | 2 | 09 Nov 2025 |
| Ops assistant | Assistant | Operations Copilot | Active | 1 | 14 Feb 2026 |
| Invoice poller | Bot | — | Inactive | 0 | 02 Apr 2026 |
| Nightly export | Bot | — | Active | 1 | 21 Jul 2026 |
API keys · Logistics sync
| Label | Created | Expires | Status |
|---|---|---|---|
| warehouse-prod | 09 Nov 2025 | 09 Nov 2026 | Active |
| warehouse-staging | 02 Mar 2026 | 02 Mar 2027 | Active |
Each account holds its own keys and its own rows in the audit log — never a person's login
What you can do
Knowledge
People
Organization-role permissions apply across the whole organization. Each department role applies only inside that department and its subdepartments.
My resources · 12 you own
8 more · full control on all of them
Need more access? Contact your organization admin.
Members — invite one or a list, set role and department on the way in, deactivate without deleting, export the roster. Verify your email domain and people join on their own.
Departments — a tree that mirrors your company, nested as deep as you need. Move one and its sub-departments move with it. What a department role can share stays inside the department.
Roles — nine to start with, or write your own. Each is drawn from 247 capabilities across twelve areas, and you can see exactly how much of that a role actually holds.
Audit Log — every change: who made it, what it was, when. Filter by entity, action, actor or date, and export the result. The log is append-only and tamper-evident, so an altered record does not stay hidden.
Settings — the defaults, in one place. One preset decides what an ordinary member can do across the whole organization — collaborative, balanced or controlled — and it takes one click, not a pass through every role. Nine sections in all, down to guest expiry.
Service Accounts — bots and assistants get their own accounts and their own API keys, under the same capability model as a person. Nothing automated has to borrow someone's login.
My Access — the same question from the other end. Anyone can open their own page and see the roles they hold, what those let them do, what they do not, and which parts are only true inside their own department.
The path a person takes
And underneath Every one of those steps lands on the audit log — and anyone can open My Access to see what they hold and where it came from.
Guests
Four ways access widens by accident, and a guest can be given none of them. Guest access can expire too — on inactivity, on a fixed limit, or both.
Sign-in
Three ways in, and a second factor on the third. No shared logins — every action on the record belongs to one account.
Service accounts
one audit log
Bots and assistants get their own accounts and their own keys, under the same capability model as a person — and their own rows in the record.
Leaving
Article 17Erasure, on request
A structured export you can take elsewhere, and deletion when you ask for it. The export names its own gaps rather than quietly leaving them out.
The record
The Trust Center holds the record this page summarises: certification, policies, the current sub-processor list, data residency, our processor register, and today's compliance posture. The record and the current privacy notice are public, with their effective dates.
The rest of a review is paper. Enterprise licences, data-processing agreements and custom terms are scoped with you, and we put the current wording in front of your legal team. Send the questionnaire, not an email thread — we answer it line by line, including the rows where the answer is no.
See Enterprise — agreements, procurement, sector-specific terms
The boundary
Even compliant, even encrypted, data can sit under a jurisdiction that isn't yours. That is a deployment question rather than a certification, and it has its own page.
The certificate answers
Examined by an external auditor, and examined again every year.
Only your deployment answers
No certificate closes these four. Where you run it does.
Four questions, one answer. Run the whole platform on hardware you control, and the jurisdiction, the compellability, the keys and the network boundary all become yours.
See how you take full control