Security Overview

Aeon AI Risk Management Corporation · effective 2026-05-01

  • TLS 1.3 enforced on every endpoint; HSTS, X-Frame-Options DENY, X-Content-Type-Options, Permissions-Policy headers set on every response.
  • Postgres FORCE row-level security with non-superuser application role. Cross-tenant insert / read / update / delete is rejected at the database layer regardless of application code.
  • Append-only audit log enforced at the database trigger level — UPDATE and DELETE on audit rows are rejected even from a superuser connection.
  • SOC 2 readiness underway. Vulnerability disclosure: security@airiskmanagement.ca.

This is a summary. The legally binding canonical version lives at https://airiskmanagement.ca/legal/security.