The Platform IT Actually Has to Run.
Marketing pages talk about features; IT directors care about the unglamorous stuff. How does SSO wire? What's the SOC 2 packet? Can I deploy on my own VPS with my own backup bucket? What happens when the sub-processor list changes? Aeion is designed so IT can defend it through procurement, deploy it through change-management, and run it without 24/7 vendor escalations.
What You Care About
Tenant lifecycle management
Create, suspend, archive, and restore tenants through the admin UI without a ticket to engineering. Multi-tenant parents — agencies, franchises, holding companies — get sub-tenant management with role-based parent-to-child access, so an agency admin sees their own client roster without engineering standing up separate deployments.
SSO configuration
SAML 2.0 IdP integration for Okta, Azure AD, Google Workspace, OneLogin, Ping, Auth0, or a custom provider, plus OIDC for modern stacks. JIT user provisioning and group-to-role mapping mean new hires get the right access the first time they sign in, SCIM 2.0 keeps the user list in sync as people join and leave, and MFA enforcement plus conditional access (by IP or device) close the gap that a standalone password policy leaves open.
RBAC and access control
Permissions are enforced at the field level, not just per collection, so you can let a manager see a salary band without exposing an SSN. Role hierarchy and custom-role definitions map to how your org actually delegates authority, admin impersonation is fully audited so support access never becomes an accountability gap, and per-tenant IP allowlisting plus session-policy controls (timeout, concurrent sessions, device limits) give security the levers they expect.
Audit log and observability
Every action is signed and tamper-evident, queryable by user, tenant, module, time, or event type — so "who did what, when" is a query, not a forensic exercise. SIEM export to Splunk, Sumo Logic, Datadog, or your tool of choice keeps it in your existing observability stack, and real-time alerting flags suspicious access patterns as they happen instead of during the next audit.
Backup and disaster recovery
Aegis' four-layer defense — a pre-destructive migration guard, continuous point-in-time recovery (~30s RPO), daily snapshots, and per-row time travel — means a bad migration or a fat-fingered delete is a restore, not an incident. Backups ship to your own S3 bucket with object-lock immutability against ransomware, and restores are verified weekly, not just taken on faith.
Deployment modes
Run hosted on Aeion's infrastructure, self-hosted on your own VPS, or a hybrid split — sensitive tenants self-hosted, everything else on Aeion. Air-gapped deployment is available for the environments that require it — talk to sales for scoping.
Sub-processor management
The sub-processor list is published with location and BAA status for every vendor in the chain, changes come with 30 days' notice, and All-Access customers get veto rights — no surprise fourth-party showing up in a security questionnaire.
Compliance documentation
SOC 2 Type II report (under NDA), ISO 27001 controls evidence, a GDPR Article 32 implementation map, a HIPAA BAA template, a pre-completed CAIQ, the sub-processor list, a penetration test summary, and monthly Aegis compliance reports — the full packet a procurement review asks for, ready before they ask.
The Aeion Features That Map to Your Mandate
Authentication & SSO
SAML, OIDC, OAuth 2.0, API keys, and JWT, with MFA, SCIM, and conditional access built in — see Authentication & SSO for the setup guide.
RBAC Architecture
Field-level permissions, role hierarchy, admin-impersonation audit, and per-tenant IP allowlisting — see the RBAC Architecture deep-dive.
Aegis Backup + PITR
Four-layer defense, your own S3 bucket, and object-lock immutability against ransomware — see Aegis Backup & PITR.
GDPR Privacy Architecture
Article 32 controls, a right-to-erasure cascade, and data residency options — see the GDPR Privacy Architecture.
PCI-DSS Tokenization
For tenants handling payment data directly — see PCI-DSS Tokenization.
Governance Module
Compliance framework tracking, control mapping, and audit-ready reporting — see the Governance module.
Platform Module
Tenant lifecycle, VPS provisioning, plan management, and multi-tenant federation — see the Platform module.
Trust Center
The procurement-team checklist with full audit-packet contents — see the Trust Center.
The Change-Management Story
Most platform deployments fail the change-management review for one of three reasons.
The Procurement Objections You're Prepared For
IT directors hit a predictable set of objections from procurement, security, and compliance teams.
Frequently Asked Questions
Each tenant is a logically isolated data store, and any Aeion customer can opt into a fully separate physical database instead. Tenant isolation is enforced deep in the platform's core data layer, not bolted on as an application-level check — a query for the wrong tenant's data isn't just disallowed by policy, it's structurally impossible to write.
Yes. SCIM 2.0 for ongoing sync. Bulk import for initial migration. JIT provisioning for users who SSO in for the first time. Mapping from IdP groups to Aeion roles is configurable per tenant.
Configurable in 30 minutes via the admin UI for Okta / Azure AD / Google Workspace / OneLogin / Ping. Custom IdP integration available with a one-hour setup call for any Aeion customer.
Yes. Per-tenant IP allowlist. Per-user conditional access policies (require corporate VPN, require managed device, require recent MFA). Office-365-style conditional access supported.
User deactivation suspends the account but preserves the audit trail. Right-to-erasure (GDPR DSR) cascades across the tenant database — removed records, anonymized references in audit log per regulatory minimum retention.
Yes. Singularity bulk-export to S3 / CSV / JSON / SQL. Per-collection export. Time-range filtered. Legal-hold export comes with HMAC-signed manifest of records included.
Every Aeion customer gets changelog notifications in the admin UI plus email notice 7 days before user-impacting changes. The All-Access plan adds a dedicated change-management portal with pre-release access for testing and 30-day notice on user-impacting changes.
Yes. Every Aeion module supports unlimited sub-tenants. Sandbox sub-tenant included on every plan. Dev / staging / production tenant trio is the recommended pattern.
Internal incident-response runbook (redacted version available on request). 1-hour critical-incident detection SLA on the All-Access plan. 72-hour customer notification per GDPR Article 33. Public postmortem within 30 days of confirmed compromise.
Yes — book a 60-minute security review with our security lead. Audit packet shipped within 5 business days. NDA available pre-call if you need it for the conversation.