Encryption in transit
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Encryption at rest where implemented
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Secure authentication
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Multi-factor authentication
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Role-based permissions
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Audit logging
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Vendor access controls
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Least-privilege principles
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Session management
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Secure document handling
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Backup and recovery
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Incident response
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Data retention controls
Controls are implemented according to engagement scope, infrastructure, and access requirements, with human oversight for sensitive workflows.
Aurelian does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or other certifications unless and until those certifications are actually obtained.