Learn how Aymo protects data with encryption, workspace isolation, secure sessions, API key protection, and responsible AI safeguards.
Aymo is built so that your data stays yours: encrypted, isolated to your account or workspace, and never used to train a model. This section covers how data is handled, how access is controlled, and what practices sit behind the platform.
Aymo does not use customer data to train models. Chats, files, and workspace content are encrypted and remain private to the account or workspace where they were created.
Data is encrypted in transit and at rest. This covers chats and uploaded files, stored API keys, and requests routed to model providers. All communication with Aymo runs over HTTPS.
Keys added through BYOK are encrypted at rest and scoped to the single workspace where they were added. Aymo does not log key values, expose keys to other workspaces, or send them anywhere except the provider the key belongs to. Keys are used for one purpose: routing your requests to that provider.
Shared workspaces use role-based permissions. Roles determine who can see shared chats, who can edit them, and who can invite new members. Personal workspaces are private and cannot be accessed by anyone else.
Each workspace keeps its own chats, members, files, usage limits, API keys, and roles. Nothing crosses between workspaces, so a client project and an internal one never share context or content.
Sessions expire automatically, and you can review active sessions and sign out of individual devices from your account settings.
Aymo runs on infrastructure from SOC 2 certified providers, with encrypted storage and databases. Internal access to production systems is restricted and logged, and deployments follow a controlled release process.
Model outputs are filtered by each provider's own safety systems. Because Aymo routes to many providers, the exact behavior varies slightly by model.
If you find a vulnerability or suspect a security problem, contact us at [hello@aymo.ai]. We review every report and respond directly.