Aymo AI

Security and Privacy

Learn how Aymo protects data with encryption, workspace isolation, secure sessions, API key protection, and responsible AI safeguards.

Aymo is built so that your data stays yours: encrypted, isolated to your account or workspace, and never used to train a model. This section covers how data is handled, how access is controlled, and what practices sit behind the platform.

Data privacy

Aymo does not use customer data to train models. Chats, files, and workspace content are encrypted and remain private to the account or workspace where they were created.

  • No training on user data
  • No selling or sharing of customer data with third parties
  • No visibility across workspaces
  • Minimal retention outside the active workspace

Encryption

Data is encrypted in transit and at rest. This covers chats and uploaded files, stored API keys, and requests routed to model providers. All communication with Aymo runs over HTTPS.

API key protection

Keys added through BYOK are encrypted at rest and scoped to the single workspace where they were added. Aymo does not log key values, expose keys to other workspaces, or send them anywhere except the provider the key belongs to. Keys are used for one purpose: routing your requests to that provider.

Access controls

Shared workspaces use role-based permissions. Roles determine who can see shared chats, who can edit them, and who can invite new members. Personal workspaces are private and cannot be accessed by anyone else.

Workspace isolation

Each workspace keeps its own chats, members, files, usage limits, API keys, and roles. Nothing crosses between workspaces, so a client project and an internal one never share context or content.

Session security

Sessions expire automatically, and you can review active sessions and sign out of individual devices from your account settings.

Infrastructure

Aymo runs on infrastructure from SOC 2 certified providers, with encrypted storage and databases. Internal access to production systems is restricted and logged, and deployments follow a controlled release process.

Content safety

Model outputs are filtered by each provider's own safety systems. Because Aymo routes to many providers, the exact behavior varies slightly by model.

Reporting a security issue

If you find a vulnerability or suspect a security problem, contact us at [hello@aymo.ai]. We review every report and respond directly.