Privacy Policy

Aeon AI Risk Management Corporation · effective 2026-05-01

  • Aeon stores customer artifacts (markdown, PDF, and Word uploads today; a Slack connector is coming) in a multi-tenant Postgres with FORCE row-level security enforced at the database layer.
  • Per-tenant ed25519 signing keys are envelope-encrypted at rest; the application never holds the master key in plaintext. Connector OAuth tokens use the same envelope-encryption scheme.
  • Data is encrypted at rest. Additional data-residency regions are on the roadmap.
  • Sub-processor list and DPA available on request to legal@airiskmanagement.ca.

This is a summary. The legally binding canonical version lives at https://airiskmanagement.ca/legal/privacy.