Security

Effective: October 6, 2026 | Last updated: October 6, 2026

Report a vulnerability: support@ajelix.com (see §12) | Service status: status.ajelix.com


1. Overview

Ajelix is an agentic AI workspace (chat, AI for Excel/Sheets/Docs/Slides/Forms, finance, marketing, analytics, PowerPoint agents) operated by SIA AJELIX (reg. no. 40203482950), Latvia. Security is designed around one principle: your content is processed to do your work, on infrastructure we own and control, in the EU — and is never exposed, reused, or trained on.


2. Compliance posture

  • GDPR: compliant as processor and controller. DPA available to all customers; all primary processing stays in the EU/EEA.
  • EU AI Act: aligned with transparency and risk-management obligations for our product class (see AI policy).
  • ISO 27001: certification in progress. Until certified, security questionnaires, this page, and the DPA are available on request.
  • Google API Services: complies with the Google API Services User Data Policy, including Limited Use requirements.

3. Infrastructure

  • AI inference: GPU servers owned by Ajelix, located in a dedicated facility in Riga, Latvia. Customer data sent for AI processing never leaves our own EU infrastructure.
  • Application hosting: Hetzner (Germany) and OVHcloud (Germany region). Provider certifications (ISO 27001, SOC 2) are inherited for their managed layers.
  • Production systems are segregated from corporate systems; all access is through an encrypted VPN with two-factor authentication, protected by firewalls.
  • Backups run on a 30–60 day cycle, encrypted, with restore procedures.

4. Encryption

  • In transit: TLS enforced on all websites and APIs.
  • At rest: data is encrypted with industry-standard encryption; user passwords and secrets are stored only as modern one-way hashes; particularly sensitive fields receive an additional layer of encryption.
  • Independent key layers protect session and access-token verification.

5. Access control

  • Least privilege; role-based access for staff.
  • An encrypted VPN with two-factor authentication is required for all production and administrative access; firewalls segment networks.
  • Access rights reviewed up to twice a year.
  • Onboarding/offboarding: access provisioned per role, revoked on departure.

6. Application security

  • Tenant isolation is enforced through multiple mechanisms: segregation at the database and storage level, with strict per-tenant access-scope checks applied to every request. Dedicated per-customer databases are available for enterprise customers.
  • Add-on integrations request the minimum OAuth scopes — only files the agent created or files you explicitly allow (see Google disclosure).
  • Secure development: mandatory unit testing, static and dynamic application security testing, multi-layer AI-assisted security review, and stress testing before release.
  • Audit logging of administrative and security-relevant actions.

7. AI-specific controls

  • No training on customer data. Your prompts, files, and outputs are never used to train AI models.
  • Inference stays in-house. Processing happens on Ajelix-owned GPU servers — not on any third-party AI platform. Exception: in exceptional situations, such as a disruption of our own infrastructure, we may use a vetted external AI provider for as long as needed to maintain the Service; see the Subprocessor List for the safeguards that apply.
  • Agent execution runs under your authorization only; file access is scoped to agent-created files or files you explicitly allow.
  • Encrypted at rest, audit-logged, and strictly access-limited.

8. Monitoring and incident response

  • Monitoring and error logging run on self-hosted infrastructure — no third-party monitoring services process our logs.
  • Incident response process is being formalized as part of the ISO 27001 certification effort. Personal data breaches are notified to affected customers within 48 hours of awareness (see DPA §7).
  • Vulnerability reports: see §12.

9. Business continuity

  • Backups every 30–60 days, encrypted, with restore procedures.
  • Service status and maintenance windows announced at status.ajelix.com.
  • Support response target: within 48 business hours for all paid customers.

10. Vendor management

  • Subprocessors are vetted before onboarding and listed publicly in the Subprocessor List. The current subprocessors are: Hetzner (Germany), OVHcloud (Germany), Stripe, Swedbank, Mailtrap (US-hosted, Standard Contractual Clauses), and Google. Our data center services in Riga, Latvia are part of our own infrastructure.
  • Vendor access to customer data is limited to what the service function requires.

11. Personnel

  • Employees receive security and data-protection training on the most important concepts.
  • Pre-employment checks on publicly available information (lawful under Latvian law).

12. Reporting a vulnerability

Email support@ajelix.com with details and steps to reproduce. We do not operate a bug bounty program, but we respond to all vulnerability disclosures and remediate confirmed issues. We ask that you do not test against other customers’ accounts or access data other than your own.


13. Security contact

SIA AJELIX, reg. no. 40203482950, Peldu iela 7, Jelgava, LV-3002, Latvia | support@ajelix.com