Aeion Files for Compliance Document Vaults

Auditors don't care that you store contracts. They care whether you can prove who accessed what, when, and why — and whether DLP would have caught a leak before it left the company. Compliance vaults are a distinct workload from general file sharing: every event logged, every file DLP-scanned, every violation quarantined for review. Box Governance + Egnyte + NetDocuments cost $30-80/user/month. Aeion Files delivers DLP scanning, activity audit logging, and configurable retention policies on your own S3/R2/GCS bucket.

What a Compliance Vault Requires

`

Walkthrough — Healthcare PHI Vault

`

Walkthrough — Financial Services Document Retention

`

Walkthrough — SaaS SOC 2 Evidence Vault

`

FAQ

Not natively managed by Aeion today. Since you bring your own S3/R2/Azure bucket, you can enable Object Lock directly on the bucket yourself — Aeion Files doesn't yet set retention-mode or legal-hold flags through the storage API.

Every file/space event (create, read, update, share, download, version restore) is logged with actor, action, and timestamp; share-link access also captures IP + user agent. There's no cryptographic hash-chaining, sequence-integrity verification, or built-in SIEM export yet — pull the log via the API if you need to feed a SIEM.

Not implemented today. There's no matter/custodian tracking, hold-scoped retention override, or release-approval flow in Files or the Legal module.

Not implemented today. DLP scanning flags files containing SSN/credit-card-shaped/secret-key patterns and marks them quarantined for admin review, but there's no field-level or view-time redaction engine, and no de-identification-on-export feature.

Not today. The storage layer has an encryption hook reserved for a future KMS integration, but it isn't wired to a real key-management provider — encryption at rest depends entirely on what your underlying bucket provides natively.

That's your bucket's native S3/R2 replication, configured on your own storage account — not something Aeion Files manages or requires.

Not as a distinct account type. In practice, issue a password-protected, view-only share link scoped to the relevant folder with an expiration date — every access is logged with IP and user agent.

No dedicated data-subject-erasure workflow (with a formal destruction certificate) today. An admin can locate and delete the specific documents; this is a manual process for now.

No automated per-jurisdiction compliance-profile engine today. DLP patterns and retention policies are configured per-tenant, not per-jurisdiction — mapping specific state/country requirements to policy is a manual setup step.

Singularity handles bulk file + folder migration; check current connector coverage for your specific source system before committing to a timeline.

Compliance vaults without the $80/user fees.