Security & Compliance — Aeion Finance
Finance data is the most sensitive data your company holds: bank credentials, payroll PII (SSNs, addresses), tax IDs, signed contracts, audit-relevant journal entries. Aeion ships institutional-grade controls by default — immutable double-entry posting, role-based access with separation-of-duties enforcement, AES-256 encryption at rest, signed audit events, SOX-compliant audit retention that scales by tier (30 days Starter, 1 year Pro, 7 years Enterprise), GDPR erasure cascade, and customer-managed encryption keys (CMK) for Enterprise tier.
Immutable Double-Entry Posting
The foundation of audit-grade finance.
Role-Based Access Control + Separation of Duties
Six built-in finance roles with non-overlapping permissions:
Encryption — At Rest, In Transit, At Use
`
Audit Trail — Signed Events + Tiered Retention
Every finance mutation generates a signed audit-event record, capturing who did what, when, from where, and what changed.
Compliance Mapping
`
Bank Credential Handling — The Most-Sensitive Credential
`
FAQ
Yes for Enterprise tier — NDA required. Annual audit cycle; latest report shared on request via security@aeionos.com.
Annual third-party pentest via reputable firm; quarterly internal red-team exercises. Summary report available to Enterprise customers.
Public bug bounty program; finance-module reports prioritized P1. See /security/bug-bounty for scope + payout tiers.
Enterprise tier supports dedicated, isolated infrastructure — your own private database and storage layer, fully separated from other tenants. Air-gapped deployments require a custom engagement; contact security@aeionos.com.
Enterprise tier supports BYOK via AWS KMS, GCP KMS, Azure Key Vault. You rotate keys on your own schedule; revocation immediately disables decryption (effectively destroying data without erasure).
Aegis ships continuous point-in-time recovery (~30s RPO) + cross-region S3 replication (Enterprise). RTO target: 30 min for full-tenant restore; 5 min for table-level restore. See /platform/aegis for the full backup architecture.
The DSR handler cascades across every entity that references the subject (employees, vendors, customers, contacts), checks SOX/IRS retention obligations (7-year minimum on financial records — these CANNOT be erased), tombstones non-required PII, and generates an erasure receipt plus audit-log entry. Some financial records (1099s, W-2s) are legally required to be retained for 7 years and cannot be erased — the DSR handler explains this to the requester.
$10M Tech E&O + $5M Cyber liability. Certificates of insurance available to Enterprise customers on request.