AIM
SDK & integrations

Build on AIM. Not next to it.

The AIM SDK exposes authentication, permissions, data models, UI hooks, webhooks. Whether you're an integrator or publisher, you work with a platform designed to extend ยท without breaking sovereignty.

SDK scope

Four technical pillars.

Authentication & SSO

SAML, OIDC, SCIM. Native integration with your existing IAM (Microsoft Entra, Okta, Keycloak, ADFS). Compatible with Business and Enterprise tiers.

Data models

Exposed schemas: assets, classes, modules, tickets, logbook entries, inventory views, drive files. REST API + GraphQL + real-time webhooks.

UI Hooks

Components embeddable in the asset record, ticket, logbook. Branding and permissions respected. Sandboxed iframe or native Web Component.

Webhooks & Events

Push events: asset created, ticket closed, logbook signed, IoT alert. Ideal for plugging your internal workflows or sovereign Make/Zapier.

Integration types

From plug-and-play to custom.

Three modes depending on scope complexity. Time-and-materials available for architecture and steering phases.

๐Ÿš€ Plug-and-play

Certified plugins available in the Marketplace. Activation in a few clicks, guided configuration, no development required.

๐Ÿ› ๏ธ STANDARD integration

Authentication, permissions, data models, UI hooks. Via documented SDK and API. Ideal for plugging a standard ERP, IAM, or classic IoT.

๐Ÿ—๏ธ COMPLEX integration

Custom ERP, proprietary IoT, video, advanced BIM, complex SSO, multi-system orchestration. Dedicated SOW, AlpiVault team involved.

Time-and-materials available for architect / security / integration. Subcontracting via AlpiVault Certified partners only (list published on Partner Portal). The Partner remains fully responsible.

Audit & security (GTC ยง4)

Audit is mandatory in 4 cases.

Client data security is non-negotiable. Any plugin touching real data goes through an audit before production deployment.

(a) Client data

Any access to Client Data beyond simple metadata triggers mandatory audit.

(b) Personal data

Processing of Personal Data (per nLPD/GDPR) triggers mandatory audit and a DPA.

(c) Sensitive flows

Modification of IAM/SSO flows or elevated permissions: mandatory audit before deployment.

(d) Business / Enterprise tier

Any Business or Enterprise qualification triggers mandatory audit (Starter exempt outside cases a/b/c).

๐Ÿ” Standard application audit

Security checklist, dependency review, automated vulnerability tests, application audit. Required for most Business plugins.

๐Ÿ›ก๏ธ Advanced tests (pentest)

Targeted pentest, infrastructure review, deep intrusion tests. Required for Enterprise and significant-risk plugins.

๐Ÿ” Re-test after fix

The partner fixes vulnerabilities within reasonable timeframes proportional to criticality (GTC ยง4.4). Re-test included in initial work.

๐Ÿ“… Annual audit

Periodic re-test based on the chosen certification level. Terms set in SOW. Non-compliance โ†’ suspension or removal (GTC ยง4.5).

Partner journey

Five steps to publish your plugin.

Initial scoping

First call to qualify your plugin: scope, target tier, data concerned.

SDK access

Onboarding on the Partner Portal, access to technical docs and sandbox environments.

Development

Build the plugin with AlpiVault technical support available. T&M possible for sensitive phases.

Audit & SOW

Tier-appropriate security audit, SOW signature (commission, events, window, SoR).

Publication

Marketplace highlight, optional certification (SILVER / GOLD / PLATINUM), continuous support.

Ready to ship on AIM?

30 minutes to discuss your plugin, target tier, SOW and certification steps.

Book my slot โ†’