Aeion Files Data Sovereignty

Most file-sharing vendors require you to give them custody of your data. They host the bytes, they hold the encryption keys, they control the access logs, they decide what jurisdiction your data lives in. Aeion Files is built backwards — the bytes live in your cloud account, encrypted with your keys, in your chosen region, billed to you, with audit logs in your control plane. Aeion is the intelligent metadata + access layer. The data is yours, end-to-end, by construction.

The Sovereignty Stack

`

Customer-Managed Keys (CMK)

`

Vendor Exit Plan

`

Compliance + Audit Posture

`

FAQ

No. Bytes live in customer's bucket. Aeion stores only metadata + indexes in customer's Postgres.

No. CMK lives in customer's KMS. Aeion has IAM role to use the key via KMS API — never holds key material.

Per-tenant scope. Compromise of Aeion infra doesn't give attacker access to customer's S3 bucket (customer IAM still in customer's control).

Customer revokes the role. Aeion immediately loses access. Customer's data unaffected.

Only if customer configures it (e.g., cross-region replication). Aeion doesn't move data across regions without customer config.

No. Aeion staff have no direct access to customer bucket. SOC 2 break-glass procedure exists for emergencies — auditable, customer-notified.

Per-cloud-provider KMS (AWS KMS, Azure Key Vault, GCP KMS). For HSM-grade, Customer can use external KMS via XKS / EKMS bridges.

Per-tenant configurable cross-region replication. Aegis backup tier covers DR scenarios.

Your data lives in your bucket. You can stop using Aeion immediately and continue operating with raw S3.

No. Per-tenant data is never used for model training. Embedding generation (when enabled) uses customer's own AI provider key.

Published at /security/subprocessors. Customer-notified of changes.

Aeion's infrastructure + processes. Customer's infra (S3, KMS) is customer's own SOC 2 scope.