September 21, 2026

Security & Governance

AIM is designed around separation of responsibilities: the customer controls its AI provider credentials, the local WordPress installation controls private work, and AIM Network Hub receives only the data required for activation, directory/community functions and deliberately shared learning.

No public AIM OpenAI key

Customers connect their own OpenAI Platform project through WordPress Settings → Connectors. AIM should not distribute one central provider API key across unrelated customer websites. The provider key is not sent to AIM Network Hub.

Sharing scopes are explicit

Private

Working material remains on the customer installation and is not exposed through the community.

Network anonymised

Reusable learning can contribute without identifying the organisation publicly.

Network attributed

The organisation chooses to attach its identity to the contribution.

Public

Approved material can be published through the AIM website, Directory or shared Library.

Governance is more than credential separation

Separate provider credentials improve isolation and accountability, but they do not by themselves make an organisation compliant with ISO standards, SOC requirements or UK data-protection law. Each organisation remains responsible for its own governance, retention, permissions, supplier review and lawful processing.

Deployment checklist

Review hosting, WordPress roles, authentication, provider project permissions, connector access, network sharing defaults, retention, moderation, approval flows and internal policy before production rollout.