AI governance
Company posture on AI risk, data protection, security controls, and human oversight for Aigora products used in consumer insights work. Prepared for AI governance board review and for security, privacy, legal, architecture, and procurement diligence.
Version 2026-08-07. Last reviewed 2026-08-07. Public company summary. Detailed evidence available under NDA.
For AI governance boards
Responsible AI governance is part of how Aigora designs products and delivers client work. Security, data protection, and human accountability are design constraints, not afterthoughts.
Aigora provides AI tools for consumer insights and sensory science. Our systems support research exploration and synthesis under human review. They are multi-tenant, with organization-level isolation.
Aigora is SOC 2 compliant: we follow SOC 2 practices, and our infrastructure providers are SOC 2 certified. Our own independent Type II examination is in progress. The report has not yet been issued.
Client data is not used to train foundation models. Default ephemeral workspaces use a 24-hour cache unless durable storage is explicitly enabled.
Enterprise deployments use a separate MSA and DPA. Website Terms apply to the public site only.
AI outputs can still be incomplete or wrong. Citations and review tools help people inspect sources; they do not eliminate error. We recommend a bounded pilot with a separate production gate.
What we claim
- SOC 2 posture
- Aigora is SOC 2 compliant: we follow SOC 2 practices, and our infrastructure providers are SOC 2 certified. Our own independent Type II examination is in progress. The report has not yet been issued.
- Training boundary
- Client data is not used to train foundation models.
- Tenancy
- Multi-tenant products with organization-level isolation.
- Retention default
- Default ephemeral workspaces use a 24-hour cache unless durable storage is explicitly enabled.
- Authentication
- OAuth-only authentication through Google and Microsoft.
- Encryption
- Encryption in transit; encryption at rest for data stored by infrastructure providers.
- Human oversight
- Material research conclusions require human review. Systems support exploration and synthesis; they do not replace validated research decisions.
- Residual risk
- AI outputs can be incomplete or wrong. Citations and review tools help people inspect sources; they do not eliminate error.
- Contracting
- Enterprise deployments use a separate MSA and DPA. Website Terms apply to the public site only.
What we do not claim
- Finished independent Type II status for Aigora or THEUS beyond examination in progress
- Error-free AI output, or residual model error as absent
- Automatic correctness of every generated statement solely because a citation exists
- Public identification of companies that use THEUS
Intended use
- Explore and synthesize institutional research with source references for human inspection
- Support research design and prioritization, including synthetic methods that guide fieldwork rather than replace it
- Assist analysts with drafting, analysis, and training workflows under human accountability
Not intended use
- Fully automated business decisions without human approval
- Sole basis for regulated or safety-critical claims without independent validation
- Training foundation models on customer data
Security and privacy summary
Security and data protection are design constraints. Platform controls include organization isolation. OAuth-only authentication through Google and Microsoft. Encryption in transit; encryption at rest for data stored by infrastructure providers. GDPR and CCPA data-rights review available during procurement. Enterprise deployments use a separate MSA and DPA. Website Terms apply to the public site only.
Public marketing deployments currently inherit infrastructure controls from providers such as Vercel and Neon. Product runtimes may use additional services for authentication, model inference, storage, and monitoring. The complete versioned subprocessor register, including purpose and data classes, is provided under NDA during enterprise review.
Products in scope
- THEUS. Knowledge exploration with source-linked research work. Product control detail lives in the THEUS Trust Center annex. Learn more · THEUS Trust Center
- Forethought. Synthetic research support for fieldwork design and prioritization, with human review of outputs. Learn more
- AI Toolkit and training. Assistive tools and capability transfer for insights teams. Learn more
- Custom decision systems. Contracted scope defined per engagement. Learn more
Evidence availability
| Topic | Status | How to obtain |
|---|---|---|
| SOC 2 status summary | Public | This page and the company trust manifest |
| Training and retention policy | Public | This page |
| Subprocessor register (summary) | Public | Summary on this page; full register under NDA |
| Architecture and data flow | Under NDA | Request the diligence pack |
| Security testing summary | Under NDA | Request the diligence pack (scope and date of testing provided with materials) |
| AI risk assessment | Under NDA / in progress | Request the diligence pack |
| DPA / transfer terms | Enterprise contracting | Legal and procurement process |
| Evaluation metrics | Under NDA | Available when measured packages exist; request the diligence pack |
| Support, continuity, exit | Enterprise contracting | MSA and security schedule |
Recommended engagement model
- Bounded pilot on approved data with a named business sponsor
- Named user cohort, with human review required for material conclusions
- No autonomous external actions or write-back to systems of record during pilot unless explicitly agreed
- Success metrics agreed up front (quality, time, adoption, risk events)
- Separate production gate after pilot evidence
Request deeper diligence
The public company packet is available as a PDF. For architecture diagrams, full subprocessor detail, security testing summaries, and other NDA materials, use the contact form or reply to your Aigora contact and include security and privacy recipients if needed.
Aigora Governance Packet · Contact for deeper diligence under NDA · Privacy policy · Terms of service · Machine-readable trust manifest
Residual model risk remains. Material conclusions require human review.
Document control
- Version: 2026-08-07
- Last reviewed: 2026-08-07
- Next review: When SOC 2 examination status changes, or within 90 days
- Public company summary. Detailed evidence available under NDA.