AIG Trust Center
Security & compliance
How AIG protects member data — and how we take responsibility for the people and world we serve. Language below describes implemented technical controls and program commitments — not third-party audit seals or certificate IDs.
Privacy Policy · Data subject rights
Our responsibility
A responsible way of doing business
We care about our leaders, our affiliates, and the world around us. Legal, quality-minded (ISO 9001:2015 practices), GDPR-aware for data protection, and a lean operator with a LEED-aligned sustainability focus through Green Tomorrow — always developing into something members can be proud of across more than 12 locations worldwide.
Security & compliance
Technical controls in place
Practical safeguards for member data and platform integrity — encryption, access control, audit logging, and rate limits — so business stays protected as we grow.
- Encryption in transit — TLS terminated at the edge / reverse proxy; HSTS enabled in production apps and API.
- Encryption at rest — AES-256-GCM for sensitive fields; bcrypt for passwords; hosting-layer volume encryption assumed for databases.
- Access control — JWT-protected APIs for wallets, profile, and member services; admin routes require the ADMIN role.
- Audit logging — Structured audit logs for login, password change, wallet transfers, membership changes, and related events.
- Session timeout — 15-minute idle logout in the member portal; short-lived access JWTs.
- Rate limiting — Auth and sensitive stream endpoints use Redis fixed-window limits.
GDPR commitment for data protection
We commit to lawful processing, purpose limitation, and data minimization. Where GDPR applies, members may request access, rectification, erasure, restriction, objection, or portability — see our Privacy Policy.