PRODSovereign European BaaS platformOpen Dashboard →
Transparency & Trust Center

Trust Center

Our security architecture in detail below. No third-party certifications (SOC 2, ISO 27001…) are currently engaged — for a precise status update and your compliance requirements, reach out directly.

#
Certifications

Status across 8 standards

SOC 2 Type IINot yet engaged
No third-party audit in progress to date
No document to date
ISO 27001Not yet engaged
No certification in progress to date
No document to date
GDPR · DPAOn request
Sub-processing agreement negotiated on a case-by-case basis
No document to date
HIPAA BAANot yet engaged
No standard BAA available to date
No document to date
PCI DSS SAQ-DNot yet engaged
No attestation in progress to date
No document to date
FedRAMP ModerateNot yet engaged
No audit scheduled to date
No document to date
SecNumCloudNot yet engaged
No ANSSI engagement in progress to date
No document to date
C5 (Germany)Not yet engaged
No BSI engagement in progress to date
No document to date
#
Security architecture

Defense in depth · 7 layers

IN-TRANSIT ENCRYPTION
TLS 1.3, HSTS preload, certificate pinning available, AWS/Azure PrivateLink
AT-REST ENCRYPTION
AES-256 envelope encryption · BYOK via AWS KMS, GCP KMS, HashiCorp Vault, HSM PKCS#11
IDENTITY
SAML 2.0 · OIDC · SCIM 2.0 · Policy-enforced MFA · device fingerprint session binding
AUDIT LOGS
2-year retention · SIEM export (Splunk, Datadog, Elastic, Sumo) · OCSF/JSON format · immutable via S3 Object Lock
PITR
90-day point-in-time recovery · continuous WAL backups · cross-region replication
NETWORK
Cloudflare WAF · per-tenant rate-limiting · IP allowlist · L3/L4/L7 DDoS · VPC peering available
ISOLATION
Dedicated Postgres cluster per project · schema-per-project · kernel-level CPU/RAM isolation (cgroups v2)
#
Process

Accessing detailed reports

§ 01
Request

Email trust@aurabase.cloud with your context (company, sector, requirements).

§ 02
NDA

Mutual NDA signed in 10 minutes via DocuSign (standard template or your own).

§ 03
Access

Direct consultation on our detailed architecture and compliance roadmap.

§ 04
Questions

Technical deep-dive call with our Security Lead within 48 hours.

Astuce
Dedicated contact: trust@aurabase.cloud · response within 24 business hours.
#
Vulnerabilities

Coordinated disclosure & bug bounty

Public program on huntr.dev/aurabase. Bounties ranging from €200 to €10,000 based on severity. Coordinated disclosure within 90 days. Safe harbor policy for good-faith researchers.

#
Links

Complementary resources

READY TO EVALUATE?

Secure portal access within 48 hours.

Email trust@aurabase.cloud with your company details. Mutual NDA, access to detailed architecture reports, and a call with our Security Lead.

No credit card required · 500 MB free · 50,000 MAU