Trust Center

Security you can check

Aury supports people in a very personal part of their lives. That is why we work to a certified information security management system. Here you will find the certificate, what it covers and how we protect data.

ISO/IEC 27001:2022 certified

Aury Care GmbH is certified to ISO/IEC 27001:2022, the international standard for information security.

Certificate no.
DE-IS-20260240
Certification body
Proks Certification GmbH, Düsseldorf
Valid
6 February 2026 to 5 February 2029

View certificate (PDF)

The certificate’s validity can be checked via the QR code on the certificate or by e-mail to info@proks-cert.de.

Operated in the EU: Aury runs on servers in the EU.

What the certificate covers

“People, processes, and technology involved in the design, development, operation, and maintenance of the Aury digital platform and the related apps for AI-powered mental well-being services.”

It is based on the Statement of Applicability of 29 November 2025, version 1.0.1.

Security controls at a glance

Organisational security

  • A binding information security policy with defined roles and responsibilities
  • Risk management: risks are assessed and treated
  • Internal audits of the management system

People

  • Annual security awareness training for everyone who works on Aury
  • Binding rules for the use of devices and information

Access control

  • Access only as far as the task requires
  • Multi-factor authentication for privileged access to production systems
  • Defined process for granting and removing access

Infrastructure and operations

  • Encryption in transit and at rest
  • Operated in the EU
  • Backups with a defined restore procedure
  • Around-the-clock monitoring: availability is checked every few minutes, and new errors are picked up within minutes

Product security

  • No change reaches Aury until it has passed automated checks: code quality, hundreds of automated tests and a scan for leaked credentials
  • The instructions that steer Aury’s AI are version-controlled, tried in a separate test environment first, and go live only after explicit approval
  • Each release checks the live AI service while it is deployed; if the check fails, the release stops
  • A defined process to identify vulnerabilities and fix them by priority

Incidents and data

  • An incident response plan and a business continuity and disaster recovery plan
  • Policies for handling, retaining and deleting data
  • You can delete your account in the app at any time; it stops working at once and is permanently deleted after 30 days
  • A third-party management policy applies to our service providers

Sub-processors

These providers process data on our behalf. The full list, with purpose and location, is in our privacy policy and is maintained there.

See the list in the privacy policy

Documents

We send further documents to partners and business customers on request, where appropriate after a non-disclosure agreement.

Request documents

Frequently asked questions

Where does Aury run?

Aury runs on servers in the EU. The AI models run in the EU as well. Which providers are involved and where they process data is listed among the sub-processors in our privacy policy.

What does the ISO certificate cover?

The people, processes and technology behind the Aury platform and its apps: from design and development to operation and maintenance. The exact wording is above and on the certificate.

How do I get further documents?

Write to us at info@aury.co. For data protection questions, our data protection contact is at dpo@aury.co.

Contact

Last updated: September 2026