Skip to main content

Legal

Security

Last updated: 30 June 2026

Security is not an add-on at AIIM, it is a design principle. This page describes the security measures we apply to this website and our responsible disclosure process. For a description of the security architecture of deployed ILM environments, contact us directly at security@aiim-global.com.

🔒

Encrypted in transit

All communication between your browser and this Site is encrypted using TLS 1.2 or higher. We enforce HTTPS across all pages and reject plain-HTTP connections.

🏛

Sovereign by architecture

AIIM's ILM deployments are designed with zero-egress architecture, clinical and institutional data never leaves the institution's environment. This is an architectural guarantee, not a policy commitment.

🔑

Minimal data footprint

This marketing website collects only what you submit through contact and article forms. We carry no patient data, no clinical records, and no authentication credentials on this Site.

🛡

Access controls

Access to submitted enquiry data is restricted by role. Only team members who need to respond to your enquiry can access your submission. All internal access is logged.

Website Security Measures

For this website specifically, we apply the following controls:

  • HTTPS enforced site-wide with automatic HTTP→HTTPS redirection.
  • Security headers including Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.
  • No third-party advertising scripts, tracking pixels, or behavioural analytics, minimal attack surface.
  • Static site architecture, no server-side code execution, no database exposed to the public internet.
  • Form submissions relayed via encrypted API endpoint with no persistent storage on the relay service.

ILM Deployment Security

AIIM's core product, the Individual Language Model, is architected for institutional deployment with the following security properties:

  • Zero-egress guarantee: data processed by an ILM never leaves the institution's physical or cloud boundary.
  • Full audit trail: every model output is logged with reasoning chain, clinician override, and timestamp.
  • Role-based access: model access is gated by the institution's existing identity and access management infrastructure.
  • No shared model weights: each institutional deployment is isolated, one institution's data never influences another's model.
  • Data residency enforcement: ILMs can be deployed within specific jurisdictions to meet local data residency requirements.

Detailed security architecture documentation is available under NDA for qualified enterprise evaluations. Contact us at security@aiim-global.com to request it.

Responsible Disclosure

If you believe you have identified a security vulnerability in this website or in AIIM's systems, we ask that you report it to us responsibly before making any information public.

Please email security@aiim-global.com with the following information:

  • A description of the vulnerability and the potential impact.
  • Steps to reproduce the issue (including URLs, parameters, or proof-of-concept if safe to share).
  • Your name and contact information (optional, anonymous reports are accepted).

We commit to: acknowledging your report within 48 hours; keeping you informed of our assessment and remediation timeline; not taking legal action against researchers who disclose in good faith under this policy.

Please do not attempt to access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability. Do not perform denial-of-service attacks or social engineering against AIIM personnel.

Incident Response

In the event of a confirmed security incident affecting personal data we hold on this website, we will:

  • Contain and remediate the incident as quickly as possible.
  • Notify affected individuals within the timeframe required by applicable law.
  • Report to relevant regulatory authorities where required.
  • Conduct a post-incident review and implement improvements.

Compliance

AIIM Global operates in healthcare environments and understands the regulatory landscape. Our institutional deployment framework is designed with reference to:

  • HIPAA (Health Insurance Portability and Accountability Act), for US-based institutional partners.
  • GDPR (General Data Protection Regulation), for European institutional partners.
  • DPDPA (Digital Personal Data Protection Act, 2023), India.
  • Applicable national health data regulations in each jurisdiction of operation.

Compliance certifications and detailed compliance documentation are available for institutional evaluations. Please contact security@aiim-global.com.

Contact

Security Team, AIIM Global Pvt Ltd

Email: security@aiim-global.com
Vulnerability reports acknowledged within 48 hours.

Privacy Policy →Terms of Use →Return home →