Aieia is designed from the ground up to keep research data where it belongs: on your local machine. The Aieia Web Portal is used only for task control. This page explains exactly what moves, where it goes, and what controls your team and institution have over it.
Aieia can be deployed in two modes. Understanding each mode helps your IT team make the right deployment decision for your lab.
A side-by-side view of where each type of data goes in each deployment mode.
| Data type | Standard deployment mode | Private Cloud Routing |
|---|---|---|
| Screenshots | Sent to AI model (zero retention). Saved locally on device. | Sent via your AWS or GCP account to AI model. Saved locally on device. |
| Task instructions and custom instructions | AI model | Your cloud account |
| Step history (session context) | AI model | Your cloud account |
| Audit logs | Swiss servers — action metadata only, encrypted | Local device only |
| Experimental data and extracted results | Local device only — never sent to Survon | Local device only |
| Device and task management | Aieia Web Portal — task dispatch and stop only. No data access. | Aieia Web Portal — task dispatch and stop only. No data access. |
Note: The AI model provider operates a zero data retention policy for API usage. Screenshots and prompts sent to the AI model are processed and then discarded. They are not stored or used for model training. This applies to both Standard deployment mode and Private Cloud Routing.
Each time Aieia takes an action, it sends one request to the AI model. Here is what that request contains, and what it never contains.
The Aieia Web Portal is the remote interface for sending tasks to connected instrument computers and stopping running tasks. That is the full extent of what it does.
The portal has no access to audit and experiment logs, extracted data, screenshots, or session records on the instrument computer. All of that stays on the local machine and is managed by your team under your own data policies.
Every part of the Aieia stack is designed to minimize data movement and maximize your team's control over research data.
Aieia runs directly on the instrument computer with no installation required. It does not run background services, does not expose network ports, and only communicates outbound over standard HTTPS to the AI model for reasoning, and to Survon's Swiss-hosted servers for audit logs (Standard mode only).
No inbound network accessScreenshots, extracted data, session records, and audit logs (in Private Cloud Routing mode) are all stored on the instrument computer. Your IT team can manage retention, access, and deletion using your existing endpoint management policies. Survon has no access to any of this data.
Your device, your controlIn Standard mode, audit logs are stored on SOC 2 certified and HIPAA compliant infrastructure hosted in Switzerland. Logs contain action metadata only — step number, action type, timestamp, and status. No experimental data, results, or screenshots are ever included.
SOC 2 certified and HIPAA compliantAieia holds no persistent state on Survon's side. When a task ends, nothing is retained. No session history, no results, no screenshots.
Nothing retained after task completionScreenshots and task instructions are sent to an enterprise-grade AI to determine the next action. We operate a zero data retention policy. Data is processed and then discarded. It is not stored after the request completes and is not used for model training.
Zero retention policyWith Private Cloud Routing, AI inference is routed through your own AWS or Google Cloud account. The API call is subject to your cloud provider agreement and visible in your own cloud console.
Governed by your cloud agreementFor labs and institutions with strict data governance requirements, Private Cloud Routing routes all AI inference through your own AWS or Google Cloud account via Amazon Bedrock or Google Cloud Vertex AI.
This means the API call is governed by your existing cloud provider agreement, visible in your own cloud console, and subject to your institution's cloud security controls. Your infosec team has full visibility and audit capability within your own environment.
In Private Cloud Routing mode, audit logs are saved locally on the instrument computer only. Survon servers receive nothing during task execution.
Discuss Private Cloud RoutingFor security reviews, vulnerability reports, or any data handling questions, contact our security team directly.
We respond within three business days.