Compliance

SHA-256 hash chain on every action, Aikido-audited codebase, MFA-gated admin access.

SOC 2 Roadmap
Vulnerability Scanning via Aikido
Live
Aikido Security Audit Report
GDPR Aligned
Privacy by Design Architecture
SHA-256 Audit Trail
Cryptographic Integrity Verification

Technical Controls

Audit Integrity

  • 01SHA-256 Hash Chain: Every system action is cryptographically linked to the previous entry, preventing any database-level tampering.
  • 02Forensic Verifiability: Our integrity engine provides API endpoints for real-time validation of log sequence and content authenticity.
  • 03Reason Tracking: Every Human-in-the-Loop (HITL) intervention is recorded with full context — the source document, current screen state, and the specific field in question — providing a complete audit trail for compliance requirements.

Access & Identity

  • 01MFA Enforcement: Multi-Factor Authentication (TOTP) is mandatory for all administrative and operator access.
  • 02Access Control: Role-based permissions with TOTP MFA and complete audit logging with session-level granularity.
  • 03Isolated Sessions: Each terminal connection runs in a dedicated, memory-isolated instance to prevent cross-tenant data leakage.

Regulatory Readiness

HIPAA Alignment

Architected to meet technical safeguard requirements for Protected Health Information (PHI). Cryptographic audit trails provide verifiable end-to-end data integrity.

Healthcare customers sign a HIPAA Business Associate Agreement (BAA) covering PHI-specific commitments, including breach notification within 30 days of discovery. See the BAA for details.

  • SHA-256 cryptographic audit trail
  • Encryption at rest (AES-256) and in transit
  • Immutable access audit logs
  • Per-tenant data isolation

Data Governance

Retention Discipline

Terminal screen data is processed in-memory and not persisted by default; optional per-organization diagnostic capture is stored encrypted and removed with the organization. Operational telemetry is deleted on fixed schedules. We do not train AI models on your operational data.

Sovereignty Control

Production runs in the EU (Hetzner, Frankfurt / Falkenstein) by default. US and UK regions are available via dedicated AWS deployment on request. No cross-border data transfer occurs without explicit, forensically logged administrator consent.

Request Security Brief

Our security whitepaper details our SHA-256 hash-chain implementation and VPC isolation logic.

Note: Whitepaper is transmitted to authorized corporate domains only.

Request