Security
Your data. Your control. Your trust.
Data sources
We only collect publicly available business data and data you explicitly import. We do not scrape personal data without legal basis.
Customer data handling
Workspace data is isolated by tenant. We do not share your company lists, signals, or scores between workspaces. You can export or delete your workspace data at any time.
Access control
Role-based access control (RBAC) with workspace roles: owner, admin, sales manager, sales rep, analyst, reviewer, finance, support, and readonly. Every sensitive action is logged in the audit trail.
Encryption
All data in transit uses TLS 1.2+. Data at rest is encrypted by the underlying cloud provider (Cloudflare / PostgreSQL encryption).
Audit logs
We maintain append-only audit logs for account creation, CSV import, score generation, action completion, and risk checks. Logs include actor, action, target, timestamp, and source.
Data retention
Default retention follows your workspace plan settings. You can request deletion of workspace data at any time via Settings or by emailing security@cios.iai.one.
Subprocessors
We use Cloudflare (hosting, Workers, Pages, D1), and PostgreSQL-compatible providers for persistent storage. No customer data is sold or used for model training without explicit consent.
Contact
Report security concerns to security@cios.iai.one. We aim to respond within 48 hours.