Security & Compliance — Aeion Finance

Finance data is the most sensitive data your company holds: bank credentials, payroll PII (SSNs, addresses), tax IDs, signed contracts, audit-relevant journal entries. Aeion ships institutional-grade controls by default — immutable double-entry posting, role-based access with separation-of-duties enforcement, AES-256 encryption at rest, signed audit events, SOX-compliant audit retention that scales by tier (30 days Starter, 1 year Pro, 7 years Enterprise), GDPR erasure cascade, and customer-managed encryption keys (CMK) for Enterprise tier.

Immutable Double-Entry Posting

The foundation of audit-grade finance.

Role-Based Access Control + Separation of Duties

Six built-in finance roles with non-overlapping permissions:

Encryption — At Rest, In Transit, At Use

`

Audit Trail — Signed Events + Tiered Retention

Every finance mutation generates a signed audit-event record, capturing who did what, when, from where, and what changed.

Compliance Mapping

`

Bank Credential Handling — The Most-Sensitive Credential

`

FAQ

Yes for Enterprise tier — NDA required. Annual audit cycle; latest report shared on request via security@aeionos.com.

Annual third-party pentest via reputable firm; quarterly internal red-team exercises. Summary report available to Enterprise customers.

Public bug bounty program; finance-module reports prioritized P1. See /security/bug-bounty for scope + payout tiers.

Enterprise tier supports dedicated, isolated infrastructure — your own private database and storage layer, fully separated from other tenants. Air-gapped deployments require a custom engagement; contact security@aeionos.com.

Enterprise tier supports BYOK via AWS KMS, GCP KMS, Azure Key Vault. You rotate keys on your own schedule; revocation immediately disables decryption (effectively destroying data without erasure).

Aegis ships continuous point-in-time recovery (~30s RPO) + cross-region S3 replication (Enterprise). RTO target: 30 min for full-tenant restore; 5 min for table-level restore. See /platform/aegis for the full backup architecture.

The DSR handler cascades across every entity that references the subject (employees, vendors, customers, contacts), checks SOX/IRS retention obligations (7-year minimum on financial records — these CANNOT be erased), tombstones non-required PII, and generates an erasure receipt plus audit-log entry. Some financial records (1099s, W-2s) are legally required to be retained for 7 years and cannot be erased — the DSR handler explains this to the requester.

$10M Tech E&O + $5M Cyber liability. Certificates of insurance available to Enterprise customers on request.

Finance security that survives an audit.