Enterprise trust center
Compliance and assurance
AIM's published security, accessibility, data-protection, auditability, quantum-resistant cryptography, and vendor-neutrality commitments for organizational review and procurement.

Compliance Information
Freedom AIM is designed to help organizations understand their systems and make informed decisions about modernization. We take compliance and data protection seriously.
Data Protection & Security
We implement industry-standard security measures to protect your data, including:
- Encryption in-transit and at-rest
- Access controls and audit logging
- Regular security assessments
- Network isolation and least-privilege authorization
Vendor Neutrality
AIM maintains strict vendor neutrality. We do not accept payments, incentives, or partnerships from technology vendors that could influence our analysis, recommendations, or scoring. This ensures objective, unbiased insights for your organization.
Accessibility (ADA, Section 508, WCAG 2.2 AA)
AIM is built and tested against WCAG 2.2 Level A and Level AA, the Revised Section 508 standards (36 CFR Part 1194), and EN 301 549. Our published Accessibility Conformance Report (VPAT 2.5) documents conformance criterion by criterion and is available on this site as both a web page and an accessible PDF.
- Accessibility Conformance Report (VPAT 2.5) — web view
- Accessibility Conformance Report (VPAT 2.5) — accessible PDF download
- Public Accessibility Statement and barrier-reporting process
To report an accessibility barrier or request the report in an alternate format, contact [email protected]. We acknowledge accessibility reports within 5 business days.
Quantum-resistant cryptography
AIM's published quantum-resistant cryptography posture is for authenticity of signed actions across the platform. AIM-signed operational artifacts use hybrid signatures: a classical public-key signature together with a NIST FIPS 204 digital signature. Both signatures must verify.
Those signed actions appear throughout AIM — Mission Control commands, Agent Orchestration delegations, partner attestations, customer-hosted gateway commands, and other AIM-signed operational artifacts — not as a single-feature add-on.
Decision records and the platform audit trail remain sealed with SHA-384. SHA-384 is a CNSA 2.0 preferred integrity hash for this class of record. It is not a post-quantum signature scheme and is not AIM's quantum-resistant cryptography claim.
The public AIM service is not a FedRAMP authorization boundary and is not a complete CNSA 2.0 implementation. Civilian federal and Intelligence Community customers receive a packaged AIM on government-operated infrastructure or a customer enclave. Those packages inherit the same hash and hybrid-signature design so the consume path can align with civilian post-quantum transition guidance and, for National Security Systems, CNSA 2.0. Transport encryption and key-establishment remain the responsibility of the hosting environment.
Methodology for decision hashes is documented on Decision provenance. AIM does not claim that hashing is quantum-safe, that the public service is federally authorized, or that a packaged deployment is complete without the host's own cryptographic and authorization work.
Compliance Frameworks
While AIM itself is a decision-support tool, we understand that organizations may need to comply with various frameworks such as:
- HIPAA (Health Insurance Portability and Accountability Act)
- CJIS (Criminal Justice Information Services)
- FedRAMP (Federal Risk and Authorization Management Program)
- PCI DSS (Payment Card Industry Data Security Standard)
- Other industry-specific requirements
For specific compliance questions or requirements, please contact us at [email protected]