Security Overview
Aeon AI Risk Management Corporation · effective 2026-05-01
- TLS 1.3 enforced on every endpoint; HSTS, X-Frame-Options DENY, X-Content-Type-Options, Permissions-Policy headers set on every response.
- Postgres FORCE row-level security with non-superuser application role. Cross-tenant insert / read / update / delete is rejected at the database layer regardless of application code.
- Append-only audit log enforced at the database trigger level — UPDATE and DELETE on audit rows are rejected even from a superuser connection.
- SOC 2 readiness underway. Vulnerability disclosure: security@airiskmanagement.ca.
This is a summary. The legally binding canonical version lives at https://airiskmanagement.ca/legal/security.