Skip to main content

Security review

Evidence before assurance.

Security answers must match the application, data flow, providers, and controls actually in scope. This page is a procurement starting point—not a certification, audit report, or substitute for a deployment-specific review.

Current assurance boundary

AI-STORMS includes a public marketing site and separate operational applications and integrations. A control observed in one service must not be assumed to cover every other service. Security evidence is therefore evaluated against a named system, environment, data flow, and review date.

We will not use planned controls, provider defaults, or marketing copy as proof. Material requirements should be captured in the applicable agreement after technical and operational validation.

What a security review should cover

These are review domains, not claims that every listed control is already implemented in every environment.

Review 01

System and data scope

Identify the AI-STORMS applications, integrations, data categories, user roles, and deployment paths in the proposed use case.

Review 02

Access and tenant boundaries

Review how authentication, authorization, administrative access, and tenant separation are enforced in the systems that will hold customer data.

Review 03

Data lifecycle

Document collection, processing, export, retention, deletion, and provider handoffs for the exact channels and features being activated.

Review 04

Operational resilience

Confirm current monitoring, backup, restoration, incident handling, and recovery commitments before placing contractual reliance on them.

Review 05

Third-party services

Identify the providers enabled for the customer deployment and review their current terms, security documentation, and data-processing roles.

Review 06

Outreach controls

Validate consent evidence, suppression handling, sender configuration, escalation, and channel-specific approvals as separate compliance controls.

What this page does not represent

  • AI-STORMS does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or another third-party certification for the platform.
  • We do not represent that every application, table, account, or integration uses one universal access-control or row-isolation configuration.
  • We do not publish immutable-log, log-retention, backup-frequency, restoration-test, recovery-time, or recovery-point guarantees on this page.
  • We do not claim that multi-factor authentication is required for every user or administrative path unless that requirement is documented for the reviewed deployment.
  • A service provider's certification, privacy notice, region, or default setting is not automatically an AI-STORMS control or contractual commitment.
  • Security controls do not determine whether outreach is legally permitted. Consent, suppression, licensing, and channel approval require their own evidence and review.

Shared security responsibilities

  1. Define the users, territories, outreach channels, and integrations that are in scope.
  2. Minimize imported data and grant each user only the access needed for their role.
  3. Protect account credentials, review user access, and report suspected compromise promptly.
  4. Keep authoritative consent, opt-out, suppression, licensing, and campaign-approval records outside any single automation decision.
  5. Approve scripts and templates before activation and stop outreach when eligibility or source health is uncertain.
  6. Agree in writing on any security, retention, incident-response, or recovery requirement that is material to the purchase.

Procurement review

Send the systems, integrations, data types, user roles, and contractual requirements you need reviewed. Responses should be treated as point-in-time and limited to the documented scope.

hello@ai-storms.com

Responsible disclosure

Report suspected vulnerabilities without accessing another person's data, disrupting service, or retaining sensitive data. Include the affected URL, reproduction steps, and observed impact.

Submit a security report