Security · Trust & Platform

Security isn't a feature. It's the foundation.

Control and protection are built in, not bolted on. Aitronos is one AI platform underneath the tools your company already runs, so who can reach what is set in one place — your organization settings — and every decision lands on the same record.

This page is both halves: the certificate, and the controls behind it — members, departments, roles, the record of every change, and what each person can reach.

Thirty minutes, on one process of your own. Nothing to install first.

ISO/IEC 27001 compliance seal

ISO/IEC 27001:2022Certificate IC-IS-2606004
Aitronos AG · InterCert

CertifiedISO/IEC 27001:2022, externally audited
ControlledRoles, departments and per-item access
RecordedA tamper-evident audit log
PortableStructured export, erasure on request

The certificate

ISO 27001 certified. Not aligned. Not pending.

Certified means a certificate: ISO/IEC 27001:2022, number IC-IS-2606004, issued to Aitronos AG on 1 June 2026 by InterCert. What it attests is the management system — how security is actually run: risk, access, incidents, suppliers, change — examined by an external auditor against the standard.

It is not permanent, and that is its value: surveillance to 31 May 2027, recertification due 31 May 2029. It holds only as long as the audits keep passing.

The signed certificate is a document rather than a web page. Ask for it on the right, tell us who you are, and it downloads on the spot.

ISO/IEC 27001:2022

Certificate IC-IS-2606004

Holder
Aitronos AG
Issuer
InterCert
Issued
1 June 2026
Scope
Information security management system

Validity

Issued1 Jun 2026 Surveillance31 May 2027 Recertification31 May 2029

The signed certificate Exactly as InterCert issued it — PDF, 1.6 MB.

The controls

None of this is a support ticket. It's a screen your admins own.

Access lives in your organization settings, and your own administrators run it. Seven screens sit behind that tab strip — who is in your company, where they sit, what they can open, what happened, what the defaults are, what runs without a person, and what any one person actually holds. Here are all seven.

Seven screens — click a tab to switch
1 / 7
Organization Cycling · pick a screen
Team members34 users Export ▾ + Add User
Status: All ▾ Search by name, email or username
NameStatusRoleDepartmentJoined
A. MeierActiveMemberSales22 Jul 2026
R. KaufmannActiveDept. ManagerOperations22 Jul 2026
T. BrunnerActiveBilling ManagerFinance23 Jul 2026
S. FreiDeactivatedMemberIT14 Mar 2026
j.weber@InvitedMember
M. Perren
external
ActiveGuest04 Aug 2026

1 selected — bulk actions: role, department, status, export

Departments21 departments TreeOverview + New Department
  • Aitronos AG 34
    • Operations 12
      • Logistics 4
      • Planning 5
      • Field service 3
    • Sales & Marketing 9
    • Finance 6
    • IT 5
    • People & Culture 2

Expand all

Sales & Marketing

9 members

Inherited from

Top-level department — no permissions are inherited.

Sub-departments · 3

Marketing 0Customer Success 0Sales 0

Sharing scope

Department and private.

Roles9 roles ListCompare Create custom role
  • OwnerOrganization · 3 members
  • AdminOrganization · 4 members
  • MemberOrganization · 21 members
  • Department ManagerOrganization
  • Department ManagerDepartment
  • Knowledge ManagerOrganization · 2 members
  • Billing ManagerOrganization
  • Department MemberDepartment
  • GuestOrganization
Knowledge Manager OrganizationSystem

58 of 247 capabilities · 2 members

58Capabilities of 247
4Access areas of 12

58 of 247 granted23%

Knowledge11 verbs
Storage2 verbs
Chat6 verbs
Assistants6 verbs

8 areas not granted

Audit Log134 entries Export
Entity type ▾Action ▾Actor type ▾ Actor…FromTo
Date & timeActorActionEntity
12 Aug · 17:04P. Loacker
p***@a***.com
UpdatedRole · Knowledge Manager
+2 capabilities
12 Aug · 16:41A. MeierSharedKnowledge store · Pricing 2026
Sales · can view
11 Aug · 09:12R. KaufmannInvitedUser · j.weber@
Member · Sales
10 Aug · 14:58T. BrunnerRemovedDepartment · Field service
3 members reassigned
09 Aug · 08:20Ops assistant
service account
CreatedAPI key · Logistics sync
expires 09 Nov 2026

Showing 1–25 of 134 entries123

Organization settings9 sections Aitronos AG · org_7f3c…

Permission preset

Controls the default permissions for the Member role. Custom roles are not affected.

Collaborative
Balanced
Controlled
Balanced. Everyone can create their own resources, but only see what's shared with them. Best for growing teams.

Allowed email domains

Users with these domains can sign up and join without an invitation.

aitronos.comaitronos.ch + Add domain

Guest access expiry

Two clocks, either or both. Signing in resets the first.

90days without signing in
365days absolute limit
14days to reactivate
Service Accounts4 accounts + Create Service Account
NameTypeLinked assistantStatusAPI keysCreated
Logistics syncBotActive209 Nov 2025
Ops assistantAssistantOperations CopilotActive114 Feb 2026
Invoice pollerBotInactive002 Apr 2026
Nightly exportBotActive121 Jul 2026

API keys · Logistics sync

LabelCreatedExpiresStatus
warehouse-prod09 Nov 202509 Nov 2026Active
warehouse-staging02 Mar 202602 Mar 2027Active

Each account holds its own keys and its own rows in the audit log — never a person's login

My Access Balanced R. Kaufmann
Organization role:Member Department roles:Operations · Department Manager

What you can do

Knowledge

  • Create knowledge storesAnd share them inside your department
  • Delete organization-wide stores

People

  • Invite and place membersGranted in: Operations, Logistics, Planning
  • Change organization roles

Organization-role permissions apply across the whole organization. Each department role applies only inside that department and its subdepartments.

My resources · 12 you own

Logistics handbookKnowledge store
Weekly planningAssistant
Field service rotaSpace
Supplier contractsFolder

8 more · full control on all of them

Need more access? Contact your organization admin.

Members — invite one or a list, set role and department on the way in, deactivate without deleting, export the roster. Verify your email domain and people join on their own.

Departments — a tree that mirrors your company, nested as deep as you need. Move one and its sub-departments move with it. What a department role can share stays inside the department.

Roles — nine to start with, or write your own. Each is drawn from 247 capabilities across twelve areas, and you can see exactly how much of that a role actually holds.

Audit Log — every change: who made it, what it was, when. Filter by entity, action, actor or date, and export the result. The log is append-only and tamper-evident, so an altered record does not stay hidden.

Settings — the defaults, in one place. One preset decides what an ordinary member can do across the whole organization — collaborative, balanced or controlled — and it takes one click, not a pass through every role. Nine sections in all, down to guest expiry.

Service Accounts — bots and assistants get their own accounts and their own API keys, under the same capability model as a person. Nothing automated has to borrow someone's login.

My Access — the same question from the other end. Anyone can open their own page and see the roles they hold, what those let them do, what they do not, and which parts are only true inside their own department.

The path a person takes

  1. 1Invited An admin adds them, or your verified email domain lets them join on their own.
  2. 2Placed They land in a department — the branch of the tree they actually work in.
  3. 3Given a role Nine to start from, or one your admins wrote for the job.
  4. 4Granted on top Access to individual items, from whoever owns them.

And underneath Every one of those steps lands on the audit log — and anyone can open My Access to see what they hold and where it came from.

Guests

An organization-wide access mode
An all-members flag
A role or department grant
An anyone-in-the-org link
Shared with them, item by item

Four ways access widens by accident, and a guest can be given none of them. Guest access can expire too — on inactivity, on a fixed limit, or both.

Sign-in

Google Microsoft Email
Then a second step 419027

Three ways in, and a second factor on the third. No shared logins — every action on the record belongs to one account.

Service accounts

Ops assistant 2 keys · exp 09 Nov
A person's login never borrowed

one audit log

Bots and assistants get their own accounts and their own keys, under the same capability model as a person — and their own rows in the record.

Leaving

Your data, exportedArticle 20
Listed: anything it could not include

Article 17Erasure, on request

A structured export you can take elsewhere, and deletion when you ask for it. The export names its own gaps rather than quietly leaving them out.

The record

Check it yourself. Or put it in a contract.

The Trust Center holds the record this page summarises: certification, policies, the current sub-processor list, data residency, our processor register, and today's compliance posture. The record and the current privacy notice are public, with their effective dates.

Public The compliance record
Public The current privacy notice, with its effective date
Request The signed certificate, as the auditor issued it

Open the Trust Center — trust.aitronos.com

The rest of a review is paper. Enterprise licences, data-processing agreements and custom terms are scoped with you, and we put the current wording in front of your legal team. Send the questionnaire, not an email thread — we answer it line by line, including the rows where the answer is no.

See Enterprise — agreements, procurement, sector-specific terms

The boundary

One question certifications can't answer: where does your data actually live — and who else can reach it?

Even compliant, even encrypted, data can sit under a jurisdiction that isn't yours. That is a deployment question rather than a certification, and it has its own page.

The certificate answers

  • How access is governed
  • How risk is assessed
  • How incidents are handled
  • How suppliers are vetted
  • How change is approved

Examined by an external auditor, and examined again every year.

Only your deployment answers

  • Which jurisdiction your data sits under
  • Who could be compelled to hand it over
  • Who holds the keys
  • What leaves your network

No certificate closes these four. Where you run it does.

Four questions, one answer. Run the whole platform on hardware you control, and the jurisdiction, the compellability, the keys and the network boundary all become yours.

See how you take full control