Built for the procurement-team checklist.

Every CISO, DPO, and audit committee asks the same questions. This page answers them in one place — with links to the architecture pages, the actual product surfaces that enforce each guarantee, and the compliance reports you can download today. No marketing fog. No "contact us for details." If you need it for the SOC 2 packet, it's on this page.

SOC 2 Type II (audit in flight)
ISO 27001-aligned
GDPR-ready (Article 32 controls mapped)
HIPAA-capable with BAA (Enterprise)
PCI-DSS-aware (tokenized payments)
Kernel-level multi-tenant isolation
Customer-managed encryption keys (CMK)
Bring-your-own backup bucket (BYOB)
Object-lock immutability against ransomware
Immutable audit log · retention up to 7 years (Enterprise)
~30-second RPO via continuous PITR
Monthly auto-generated compliance reports

The Trust Posture in One Sentence

Aeion is a single multi-tenant platform with kernel-level tenant isolation, customer-controlled encryption, off-machine immutable backups, and a monthly auto-generated audit packet. You can hand the audit packet directly to your SOC 2 / ISO 27001 / GDPR assessor; we don't gate it behind a sales call. Six layers of architecture enforce that posture, each built into the product surface — not bolted on by an external scanner. The rest of this page is the long form for the people who need it.

The Six Layers of Aeion Trust

Identity & Access

Multi-factor authentication, SSO via SAML / OIDC, RBAC with field-level permissions, session expiry policies, IP allowlisting at the tenant level, and admin-impersonation audit trail. Every API call resolves user → tenant → permissions before the handler executes; no path bypasses the access check. Deep-dive: /architecture/rbac.

Data Isolation

Every database query is automatically scoped to the calling tenant by kernel-level interception, not by application discipline. Cross-tenant queries are a compile-time error in the type system. The tenant boundary is enforced below business logic, where it cannot be accidentally bypassed. Deep-dive: /architecture/database-wrapper.

Encryption

TLS 1.3 in transit. AES-256-GCM at rest with per-tenant keys. Customer-managed encryption keys (CMK) on Professional and Enterprise — Aeion **cannot decrypt your data without your key**. Provider API credentials (Stripe, AWS, OAuth tokens) encrypted with a separate dedicated key, rotatable independently of tenant data keys.

Backup & Recovery

Four-layer Aegis defense: pre-destructive migration guard, continuous PITR with ~30-second RPO, daily logical snapshots, per-row application time travel. Bring your own S3 bucket with object-lock immutability against ransomware. Weekly verified restores prove the backups work. Deep-dive: /platform/aegis.

Audit & Observability

Immutable audit log on every PHI / financial / admin action, signed with HMAC-SHA256, retained per regulatory minimum (7+ years on Enterprise). Every AI call traced with user, tenant, prompt, response, cost, and trace ID. Real-time anomaly detection via Neural Bus surfaces suspicious access patterns.

Compliance Posture

GDPR Article 32 controls implemented at the product surface (right-to-erasure cascade, data residency selection, consent capture, audit log of every PHI access). PCI-DSS tokenization for payment paths. HIPAA-capable architecture with BAA-signed sub-processors. Monthly auto-generated reports map controls to SOC 2 / ISO 27001 / GDPR clauses. Deep-dive: /gdpr-privacy, /pci-dss.

Compliance Posture by Framework

FrameworkStatusWhat's enforcedEvidence
**SOC 2 Type II**Readiness framework in place; CPA audit motion in flightCC1–CC9 (security · availability · processing integrity · confidentiality · privacy)SOC 2 readiness control mapping at [/compliance/soc2-readiness](/trust); monthly auto-generated control evidence; Type II report under NDA on completion
**ISO 27001**Aligned · controls A.5 → A.18 mappedISMS, access control, cryptography, operations security, supplier relationshipsQuarterly controls assessment; Annex A control evidence in /admin/platform/aegis
**GDPR**Article 32 implementedRight-to-erasure cascade, data residency, lawful basis tracking, DSR workflowDSR handling SLA documented; EU-region hosting available; DPA on request
**HIPAA**Enterprise tier with BAAPHI access logging, minimum-necessary enforcement, sub-processor BAA chainBAA signed at contract; PHI audit log queryable; BAA-only AI providers gated
**PCI-DSS**Compliant via tokenizationStripe / Adyen tokenization · we never store PANs · audit log on every chargeSAQ-A scope · Stripe / Adyen own the PCI environment
**CCPA / CPRA (California)**ImplementedConsumer rights workflow · Do-Not-Sell honored · sensitive personal info handling · 12-month retention defaultsSame surface as GDPR DSR · per-tenant configuration
**PIPEDA (Canada)**CompliantConsent capture · breach notification within 72h SLA · data residency optionCanadian-region hosting on Enterprise
**LGPD (Brazil)**CompliantDPO designation · consent capture · data residency optionBrazilian-region hosting on Enterprise
**NIS 2 (EU)**AlignedIncident reporting workflow · supply-chain risk register · MFA mandatoryQuarterly resilience report
**DORA (EU financial)**Aligned for financial-services tenantsOperational resilience · third-party risk · ICT incident reportingTier 1 financial-services contracts
**SOX (US financial reporting)**Audit-trail capableImmutable financial audit log · segregation of duties via RBAC · approval workflowsFinance module audit log queryable for restatement

Customer Data Sovereignty — What That Actually Means

Most SaaS vendors claim "your data is yours." Then they store it in shared multi-tenant tables, encrypt it with their key, back it up to their bucket, and gate exports behind a support ticket. When you cancel, you find out what "your data is yours" actually means.

Incident Response & Breach Notification

Hope nothing happens. Plan as if it will.

What You Get for the Audit Packet

SOC 2 Type II readiness pack (under NDA)

Control mapping to CC1–CC9 plus monthly auto-generated control evidence; the Type II auditor's opinion follows on audit completion (motion in flight).

ISO 27001 Annex A controls evidence

Control-by-control implementation notes with code references.

GDPR Article 32 implementation map

Every technical/organizational measure with the product surface that enforces it.

HIPAA Business Associate Agreement (BAA)

Pre-drafted on the standard HHS template; counter-signs in 24h on Enterprise.

Sub-processor list

Every sub-processor with location, purpose, BAA status, and DPA link.

Data-flow diagrams

PII / PHI / payment-card data movement across the platform and to each sub-processor.

Incident response runbook

Internal playbook redacted and shared on request.

Monthly Aegis compliance report

Auto-generated, including 90 days of backup runs, verification tests, RTO measurements, and control mappings. Customer-downloadable from /admin/platform/aegis at any time.

Penetration test summary (annual, third-party)

Methodology, scope, findings, remediation status.

Vendor security questionnaire (CAIQ / SIG / VSA)

Pre-completed Consensus Assessments Initiative Questionnaire, Standardized Information Gathering, and Vendor Security Alliance forms. Lightweight to update for your specific procurement template.

Frequently Asked Questions

Aeion's engineering practices are mapped to the SOC 2 Trust Services Criteria — the full control framework is published at /compliance/soc2-readiness. The formal Type II audit by an accredited CPA firm is the next planned compliance investment; on completion, the report will be available under NDA. Continuous control monitoring runs regardless of audit cycle status; Aegis generates monthly evidence reports any tenant can download. If your procurement requires a completed Type II report today, contact compliance@aeionos.com for current status and timeline.

Aeion is HIPAA-capable on Enterprise. BAA signed at contract; sub-processor BAA chain (AWS Bedrock, Azure OpenAI BAA, AWS Transcribe Medical) is in place; HIPAA-mode enforcement gates non-BAA AI providers from processing PHI. The compliance posture is documented at /modules/health and /architecture/gdpr-privacy.

Yes — Customer-Managed Keys are optional on Professional, default on Enterprise. Bring keys from AWS KMS, Google Cloud KMS, Azure Key Vault, or a hardware HSM. Aeion uses your key to encrypt your tenant data; if you revoke the key, we lose access instantly. By design.

Configurable per tenant. EU, US, Canada, Brazil, and Asia-Pacific regions available on Enterprise. Data — including backups and AI inference — never leaves the selected region. Default on Starter / Professional is the customer's nearest region, configurable on request.

Aegis four-layer defense: pre-destructive migration guard (Layer 1), continuous PITR with ~30-second RPO (Layer 2), daily logical snapshots (Layer 3), per-row application time travel (Layer 4). Backups stream to your own S3 bucket with object-lock immutability. Weekly verified restores prove the backups actually restore. See /platform/aegis for the full architecture.

Aegis backups are object-locked in your bucket — even credentialed access from a compromised VPS cannot delete them during the retention window. Recovery path: restore on a fresh VPS from the most recent verified snapshot, replay WAL to the moment before the encryption event, service back online typically within an hour.

A small number of named engineers on the support / SRE rotation, with break-glass approval requirements, MFA mandatory, all access logged to an immutable trail. With CMK enabled, even these engineers cannot decrypt your data without your key — they can see metadata (timestamps, row counts) but not plaintext. The list of engineers with access is published in our security policy.

No. Your data is never used to train, fine-tune, or improve any model — Aeion's, our providers', or anyone else's. All AI calls are inference-only with explicit per-tenant scope. AI providers (OpenAI, Anthropic, etc.) inherit the same prohibition via our BAA/DPA chain.

72 hours from confirmed compromise of tenant data, per GDPR Article 33 — often faster. Critical incidents detected within 1 hour on Enterprise, contained within 24 hours. Public postmortem within 30 days of any confirmed incident.

Yes on Professional and Enterprise. Coordinate with security@aeionos.com; we provide a non-production tenant, scope agreement, and findings disclosure terms. Results help everyone.

Full list at /policies under "Sub-Processor List" — every sub-processor is identified, located, and BAA / DPA-bound. We notify 30 days before any sub-processor changes.

Yes. DPA available self-serve in the admin UI for any Starter / Professional / Enterprise tenant. BAA at Enterprise (or Professional + healthcare add-on) ships pre-drafted on the HHS template; counter-signs within 24h of contract.

Self-serve export available via Singularity until cancellation. 90-day grace period after cancellation where tenant data is restorable. After the grace period, we securely wipe the tenant database. Your Aegis backups in your bucket are untouched — they remain yours forever.

Email security@aeionos.com — typical engagement is a 60-minute architecture review with our security lead, followed by NDA + materials package (SOC 2, pentest summary, CAIQ, sub-processor list). Quoted as 5–10 business days from initial contact to packet delivery.