Avoid the .ai TLD since it does not support DNSSEC http://stats.research.icann.org/dns/tld_report/ . Even if you don't care about DNSSEC, your clients will and it will come up in security reviews.
It in fact does not come up in security reviews, as you can see from the fact that virtually none of the US companies that have security teams† have signed zones. Route53, AWS's DNS service, doesn't even support DNSSEC. People are not getting dinged in audits for using AWS. I've been doing security assessments since 1997 (and vulnerability research before that) and I have never seen DNSSEC made an issue in an audit report.
† actually, there are too many words in that sentence, and I should just say "none of the US companies".
Comments
Avoid the .ai TLD since it does not support DNSSEC http://stats.research.icann.org/dns/tld_report/ . Even if you don't care about DNSSEC, your clients will and it will come up in security reviews.
It in fact does not come up in security reviews, as you can see from the fact that virtually none of the US companies that have security teams† have signed zones. Route53, AWS's DNS service, doesn't even support DNSSEC. People are not getting dinged in audits for using AWS. I've been doing security assessments since 1997 (and vulnerability research before that) and I have never seen DNSSEC made an issue in an audit report.
† actually, there are too many words in that sentence, and I should just say "none of the US companies".
You can always use a .ai for marketing and have a less attractive dot com for anything critical.