Public experience
181 mapped capabilities, eight product walkthroughs, source-labeled prices and forms that do not activate billing.
TRUSTA public, honest view of how AION presents security, privacy, AI, continuity and procurement readiness. Implemented controls are separated from customer- and country-specific validation.
Every statement uses one of three states: public experience, scope to validate and claims AION does not make.
181 mapped capabilities, eight product walkthroughs, source-labeled prices and forms that do not activate billing.
Uses approved commercial sources, blocks sensitive actions, rate-limits requests and falls back safely without external AI.
A request stores submitted fields, selected configuration and consent so AION can respond to the opportunity.
Identity, isolation, encryption, retention, residency, backup, monitoring and testing are confirmed for the integration.
SLA, support, RTO/RPO, schedules, escalation, continuity and responsibilities belong in offer and contract.
This edition does not claim ISO 27001, SOC 2, PCI DSS, FedRAMP or another certification without published evidence.
The public model follows a discipline inspired by AI risk governance: govern, map, measure and manage. This is not a claim of NIST certification.
Approved sources, safety instructions, explicit scope and human accountability.
Connect the question to catalog, modules, plans and relevant conditions without browsing private data.
Bounded size, rate, history and output reduce abuse and exposure.
Emergency, secret or device-control requests receive a safe response and human path.
The catalog, guides and assessment can be used without creating an account.
Question text, limited history and retrieved commercial context go to the AI provider with response storage disabled. Catalog mode remains available if it fails.
Contact, company, country, segment, timeline, notes, consent and commercial selection are recorded to respond and validate scope.
Access, correction or deletion requests use the published channel. Retention, location, processors and transfers are specified in the applicable notice and contract.
Roles, least privilege, authentication, joiner/mover/leaver, sessions and administrative separation.
VALIDATE →Input validation, limits, origins, error handling, secrets and dependencies.
VALIDATE →Purpose, minimization, encryption, retention, location, deletion and authorized access.
VALIDATE →Environments, availability, backups, restoration, logging, patches and continuity.
VALIDATE →Shifts, escalation, dual control, evidence, training and incident response.
VALIDATE →Processors, cloud, AI, telecom, hardware, support and exit obligations.
VALIDATE →Data protection, video surveillance, biometrics, contracts, tax and local operation.
LOCAL REVIEW REQUIREDCountry law and consent, currency, invoicing, support and data transfers.
LOCAL REVIEW REQUIREDState and sector requirements, privacy, biometrics, accessibility, insurance and terms.
LOCAL REVIEW REQUIREDGDPR, AI Act where applicable, controller roles, transfers, accessibility and residency.
LOCAL REVIEW REQUIREDLGPD, legal basis, processors, rights, currency, tax and Portuguese support.
LOCAL REVIEW REQUIREDThe interface includes keyboard navigation, labels, visible focus, semantics, contrast and reduced motion. It is designed using WCAG 2.2 practices; it does not claim formal conformance without a published independent audit.
WCAG 2.2 ↗Availability, maintenance windows, support, escalation, backup, restoration, RTO, RPO, degraded mode and data exit must become measurable commitments in the offer and contract.
NIST CSF ↗Request a technical session and a trust package tailored to your industry, country, integration and operating model. The request does not activate billing.