Trust Center

Security, privacy, and compliance at Aidlab

Aidlab builds connected health and wellness products. This page collects the public documents, security practices, and disclosure routes that help customers and partners review how Aidlab handles product trust.

Product trust

What we publish today

This section is intentionally conservative. It lists current public evidence and avoids certification claims that require an external audit or registry listing.

Compliance documents

EU Declaration of Conformity documents are available for Aidlab hardware. Additional documents can be shared during partner or procurement reviews when applicable.

Security controls

The Aidlab website uses HTTPS, security headers, and a published vulnerability reporting route. Cloud security documentation is being prepared for CSA STAR Level 1.

Privacy and GDPR

Aidlab publishes a privacy policy describing data processing, user rights, and contact routes for privacy requests.

Product positioning

Aidlab trust claims are scoped to the product and market where they apply. We do not claim SOC 2, HIPAA certification, FDA clearance, or current ISO certification on this page.

CSA STAR

CSA STAR Level 1 self-assessment

Aidlab is preparing a CSA STAR Level 1 self-assessment using the Cloud Security Alliance CAIQ questionnaire.

CSA STAR Level 1 in progressSelf-assessment

CSA STAR Level 1 is a self-assessment path, not an audit certification. Aidlab will only claim a public CSA STAR registry listing after the CAIQ answers have been completed, reviewed, and submitted.

  • Evidence collection for access control, encryption, logging, backups, vendor management, incident response, and data retention.
  • Internal review of claims before public submission.
  • Registry wording will change from "in progress" to "listed" only after public CSA confirmation.
Learn about CSA STAR
Security

Security and data protection

Public summary of controls Aidlab can currently describe without overclaiming. Detailed evidence is being mapped for the CSA STAR Level 1 CAIQ.

Encryption

Aidlab serves public web traffic over HTTPS/TLS. Evidence for cloud storage and database encryption is being documented before broader CSA STAR registry claims are made.

Access control

Production and administrative access is limited to authorized team members. Access-control evidence, offboarding checks, and auditability are part of the CSA STAR evidence pack.

Data export and deletion

Users can request privacy and deletion support through Aidlab's public contact route. Product data export guidance is available in Aidlab support materials where supported by the product.

GDPR and privacy rights

Aidlab publishes a Privacy Policy describing processing purposes, user rights, and contact routes for privacy requests.

Read Privacy Policy

Subprocessors

A public subprocessor list is planned as part of the Trust Center evidence work. Until published, B2B customers can request vendor context during procurement review.

Vulnerability disclosure

Security reports are accepted by email and through the published security.txt route. Reports should include affected URLs, reproduction steps, and potential impact.

Medical and wellness disclaimer

Aidlab public trust claims are scoped by product and market. We do not claim FDA clearance or medical-device status on this page unless a product-specific document supports that exact claim.

CE and FCC documents

EU Declaration of Conformity documents are published below. FCC and other market-specific documents can be shared during procurement review where applicable.

Documents

Compliance documents

Download public conformity documents. If you need procurement documentation that is not listed here, contact Aidlab.

Responsible disclosure

Report a security issue

Aidlab welcomes good-faith vulnerability reports and publishes a machine-readable security contact at /.well-known/security.txt.

What to include

  • Affected product, URL, endpoint, app version, or device context.
  • Reproduction steps and expected impact.
  • Your preferred contact email for follow-up.

Please do not access, modify, delete, or share data that does not belong to you. Avoid automated high-volume testing against production systems.

Email a security report

Last updated: June 30, 2026. This Trust Center is a public summary and does not replace signed customer agreements, privacy terms, or product-specific regulatory documentation.

Aidlab™ jest zarejestrowanym znakiem towarowym. Copyright © 2026