Aneo B.V.

Security Overview

This page explains how Aneo B.V. protects customer data and operates aneo products securely. It applies to aneo.io and all subdomains and aliases operated by Aneo B.V., including examples such as app.aneo.io, api.aneo.io, docs.aneo.io, status.aneo.io, and future subdomains under *.aneo.io. Security is a shared responsibility: we secure the platform, and customers configure access, review outputs, and manage users.

Last updated: 24 June 2026

1. Summary

Aneo B.V. designs its public website, Framework-Pro, IncidentAI, and related operations with security and privacy as core requirements. The controls below summarize the current approach and may evolve as products, infrastructure, providers, and customer plans change.

  • Core product data is intended to be processed in EU regions on managed cloud infrastructure where supported by the relevant provider and customer plan.
  • Primary product data stores may use Supabase in EU regions, with supporting Google Cloud Platform services for hosting, compute, storage, and related infrastructure.
  • The public website is designed for Cloud Run deployment on Google Cloud. Domain, DNS, CDN, or legacy website services may use other listed subprocessors where applicable.
  • Authentication can use Firebase Authentication and federated sign-in providers such as Google, Microsoft, and LinkedIn where enabled.
  • AI features use vetted model providers such as OpenAI for model inference. Customer Content is not used to train foundation models unless customers opt in or agree in writing.
  • Business systems may include Google Workspace, HubSpot, Google Analytics 4 subject to consent, payment providers, and other subprocessors listed on the Sub-processors page.

2. Governance

Security and privacy responsibilities are assigned within Aneo B.V. Policies and practices are reviewed periodically and adjusted as the business, products, providers, and risks change.

  • Leadership oversight of security and privacy.
  • Defined roles and responsibilities for security and privacy.
  • Confidentiality obligations for personnel and contractors.
  • Security and privacy awareness for personnel.
  • Employee background checks where legally permitted and appropriate to role.
  • Vendor review before onboarding material service providers.
  • Documented incident response, escalation, and post-incident improvement practices.

3. Data residency and isolation

Aneo B.V. aims to keep core product data in EU regions where practical and supported by the relevant provider, product configuration, and customer plan. Google Cloud Platform projects and Supabase databases may be provisioned in EU regions.

Customer projects, accounts, and workspaces are logically separated using product and infrastructure controls. EU data residency and zero-retention modes may be available on supported plans or configurations.

4. Encryption

External connections use TLS 1.2 or higher where supported. Databases, backups, object storage, and infrastructure services use industry-standard encryption at rest where supported by the provider and appropriate to the processing.

Key management follows cloud provider best practices and access restrictions appropriate for the system.

5. Identity and access management

Aneo B.V. uses role-based access control, least-privilege practices, unique user accounts, restricted administrative access, and centralized identity controls for corporate systems. Administrative access requires multi-factor authentication where available.

Customer organizations are responsible for managing their own users, identity provider configuration, permissions, and account access hygiene.

  • Role-based access control and least privilege.
  • MFA for administrative access where available.
  • Just-in-time elevation and time-bound production access where feasible.
  • Centralized identity for corporate systems through Google Workspace.
  • Session management and idle-timeout controls where supported.

6. Network security

Infrastructure uses managed cloud controls and network protections appropriate to the relevant product, provider, and deployment model.

  • Private networking, security groups, restrictive firewalls, and managed perimeter controls where supported.
  • Segmented environments for development, staging, and production.
  • Web application firewall, rate limiting, and abuse-prevention controls on public endpoints where appropriate.
  • DDoS protections provided by cloud, CDN, and edge layers where configured.
  • Monitoring of capacity, performance, and service health.

7. Application security

Product development follows secure development practices intended to reduce security defects and make changes traceable and reversible.

  • Secure software development practices with code review and dependency review.
  • Secrets management, rotation practices, and avoidance of secrets in source code.
  • Automated testing integrated into CI where applicable.
  • Change management with approvals, deployment controls, and rollback planning.
  • Security review for material changes and third-party integrations.
  • Periodic third-party penetration testing or external security review as the product and plan scope require.

8. Vulnerability management

Aneo B.V. monitors vulnerabilities in code, dependencies, infrastructure, and providers, and prioritizes remediation based on severity, exploitability, exposure, and customer impact.

  • Dependency and infrastructure vulnerability monitoring.
  • Prioritized remediation based on risk and exploitability.
  • Emergency patch process for critical vulnerabilities.
  • Tracking of remediation actions and verification where appropriate.
  • Good-faith external reports handled through the Responsible Disclosure policy.

9. Logging and monitoring

Security-relevant logs and operational telemetry are collected to operate, troubleshoot, monitor, secure, and improve the Offerings. Access to logs is restricted based on need.

Retention is time-bound and depends on product configuration, security needs, customer agreement, and legal obligations.

  • Centralized collection of security-relevant logs where supported.
  • Alerting for anomalies, suspicious activity, and operational issues.
  • Time synchronization and secure log retention.
  • Restricted and audited access to logs.
  • Operational telemetry for service reliability, abuse prevention, troubleshooting, and product security.

10. Incident response

Aneo B.V. maintains incident response practices for suspected security incidents, including investigation, containment, remediation, recovery, communication, and post-incident improvement.

If a personal data breach affects Customer Personal Data, Aneo B.V. will notify affected customers without undue delay and, where applicable, within the timeline described in the DPA or agreement.

  • Documented incident response plan with defined roles.
  • Investigation, containment, eradication, recovery, and communication workflows.
  • Post-incident review and corrective actions.
  • Breach notification support as described in the DPA and applicable agreement.

11. Business continuity and disaster recovery

Aneo B.V. uses backup and recovery practices appropriate to the relevant system, provider, product plan, and signed agreement. Backups are protected by access controls and encryption where supported.

Recovery targets depend on product plan, architecture, provider capability, and agreement. RPO and RTO targets can be shared on request for supported plans.

  • Regular backups with encrypted storage where supported.
  • Periodic restore testing where appropriate to the product and provider.
  • Redundant managed infrastructure within selected regions where supported.
  • Capacity and performance monitoring.
  • Documented continuity and recovery procedures.

12. Data lifecycle

Customers own their Customer Content. Export tools are available during an active subscription where supported by the product. Configurable retention may be available for certain product areas or plans.

On termination, Aneo B.V. deletes or de-identifies Customer Personal Data from active systems within 30 days and from backups within 90 days unless retention is required by law, security, dispute, tax, audit, or agreement. See the Data Processing Agreement for more detail.

13. Product security features

Product security features vary by product, plan, and configuration. Supported features may include identity provider sign-in, role-based permissions, project scoping, audit trails, session controls, and advanced administrative controls.

  • Single sign-on or federated sign-in with Google, Microsoft, and LinkedIn via OAuth where enabled.
  • Role-based permissions and project or workspace scoping.
  • Audit trails for key actions where available.
  • Session management and device awareness where supported.
  • IP allowlist and advanced controls may be available on supported plans.

14. AI safeguards

AI-assisted features include product constraints, provider review, data handling controls, and human review expectations. AI outputs should be reviewed before use in policies, incident decisions, customer communications, legal analysis, or compliance workflows.

Customer Content is not used to train foundation models unless the customer opts in or agrees in writing. Zero-retention options for certain AI prompts and outputs may be available on supported plans.

  • Safety filters and product controls for prompts and outputs.
  • Human review required for material actions, policy text, incident decisions, and compliance evidence.
  • No representation that AI output is legal advice, a security guarantee, or a compliance certification.
  • EU data residency and zero-retention options where supported.
  • More detail is available in the Responsible AI page.

15. Third-party risk and sub-processors

Aneo B.V. reviews material vendors before onboarding and uses contractual safeguards, data protection terms, and security measures appropriate to the service. Sub-processors may include cloud hosting, database, authentication, identity, AI model inference, CRM, email, analytics, and payment providers.

The current provider list is maintained on the Sub-processors page. Where required by agreement or law, we provide advance notice for material sub-processor changes and a process for objections.

  • Security and privacy review before onboarding material vendors.
  • DPAs, SCCs, or other transfer tools where required.
  • Ongoing monitoring of vendor security posture where appropriate.
  • Current list at https://www.aneo.io/subprocessors/ with advance notice for changes where applicable.

16. Compliance and best practices

Aneo B.V. aligns security practices with ISO/IEC 27001 and NIST CSF principles. Unless explicitly stated in writing, this page does not claim certification, audit attestation, or compliance approval.

Data subject rights and data processing assistance are described in the Privacy Policy and Data Processing Agreement.

17. Shared responsibility

Customers are responsible for secure configuration, identity provider controls, user permissions, endpoint security, exported files, approval workflows, and the accuracy and lawfulness of Customer Content.

Customers should not upload prohibited or highly sensitive data unless it is lawful, necessary, and covered by a written agreement.

  • Configure roles and permissions for least privilege.
  • Keep your identity provider secure and enforce MFA for your users where available.
  • Control who can export data and approve policy text.
  • Review AI outputs, generated documents, incident summaries, and recommended actions before use.
  • Follow the Acceptable Use Policy and applicable customer agreement.

18. Responsible disclosure

Good-faith vulnerability reports help keep aneo customers safe. Security reports can be sent to rd@aneo.io with enough detail to reproduce and assess the issue. If that address is unavailable, send the report to hello@aneo.io and include Responsible Disclosure in the subject line.

The Responsible Disclosure page explains reporting expectations, safe-harbor conditions, response timelines, and out-of-scope testing.

19. Contact

Security questions can be sent to security@aneo.io.

Responsible disclosure reports can be sent to rd@aneo.io.

Privacy questions can be sent to privacy@aneo.io.

20. Changes

We may update this Security Overview as our practices, products, providers, infrastructure, and safeguards evolve. The Last updated date shows the current version. Continued use after changes means you accept the updated page where permitted by law and applicable agreement.