AeroSelect Trust Center
In aviation, safety is not a feature, it is the foundation.
We apply the same uncompromising standard to how we protect your data.
TLS 1.3
Encryption in Transit
AES-256
Encryption at Rest
< 60 min
Recovery Point Target
4 hours
Recovery Time Target
95%+
Uptime Target
EU (Germany)
Data Hosting
EU-Sovereign Infrastructure
Your data is hosted in Germany on enterprise-grade infrastructure under GDPR. Some processing is carried out by sub-processors outside the EU (for example AI-powered CV analysis by OpenAI in the USA); all such transfers are covered by EU Standard Contractual Clauses. See the sub-processor list below for who processes what and where.
German Data Centre
Our infrastructure is hosted by NetCup in Germany, in a data centre with redundant power, cooling, and network connectivity.
ISO 27001 Hosting Provider
Our hosting provider, NetCup, holds ISO 27001 certification for its information security management system.
EU Data Sovereignty
All primary data storage and processing occurs within the European Union. No personal data is transferred to or stored in non-EU jurisdictions without an explicit legal basis.
Responsible AI by Design
AeroAI powers intelligent CV parsing and candidate matching. We maintain strict governance to ensure AI is used ethically, transparently, and under human oversight.
No-Training Guarantee
AeroAI uses the OpenAI API exclusively. Per OpenAI's API Data Usage Policy, data submitted via the API is not used to train or improve OpenAI models. Your candidate data remains yours.
Human-in-the-Loop
All AI-generated recommendations, scores, and assessments are advisory only. Final hiring decisions always require human review and approval. AeroAI augments, but never replaces, human judgement.
Data Minimisation
We limit the data sent to the AI service to what is necessary to parse and structure a CV for the task at hand.
Defence in Depth
Multiple layers of technical controls protect the Platform and your data at every level: in transit, at rest, and in operation.
Encryption in Transit
All connections are secured with TLS 1.3, and HSTS headers enforce encrypted connections.
Encryption at Rest
Stored data is encrypted at rest using AES-256.
Regular Backups
We take regular backups of the database. Backups are held within the European Union.
Logical Tenant Separation
Each customer's data is logically isolated at the application and database level. Row-level security and tenant-scoped queries prevent cross-tenant data access.
Built to Recover
Our operational resilience framework ensures rapid detection, response, and recovery from any incident, minimising impact on your recruitment operations.
Recovery Targets
We aim for a Recovery Point Target of under 60 minutes and a Recovery Time Target of 4 hours, so that in the event of a failure data loss and downtime are kept low. These are operational targets rather than guaranteed service levels.
Error Monitoring
Application errors and service health are monitored, so that issues are surfaced and can be acted on.
Sub-Processors & Partners
We carefully vet every third-party service that touches your data. Below is a complete list of our sub-processors and their compliance posture.
| Provider | Service | Location | Standards & Certifications |
|---|---|---|---|
| NetCup | Infrastructure & Hosting | Germany | ISO 27001, GDPR |
| OpenAI | AI Processing (API) | San Francisco, USA | SOC 2 Type II, API Data Policy (no training) |
| Stripe | Payment Processing | Dublin, Ireland (EU) | PCI DSS Level 1, SOC 2 Type II, GDPR |
| Mailgun | Transactional Email | USA (EU region available) | SOC 2 Type II, GDPR, DPA |
Questions about Security?
Our team is available to discuss your specific security and compliance requirements. Enterprise customers can request a detailed security questionnaire response.
AeroSelect UG (haftungsbeschränkt) · Berlin, Germany