PRODPiattaforma BaaS europea sovranaApri Dashboard →
Centro per la trasparenza e la fiducia

Centro fiducia

La nostra architettura di sicurezza in dettaglio di seguito. Al momento non sono attive certificazioni di terze parti (SOC 2, ISO 27001...): contattaci direttamente per un aggiornamento preciso dello stato e dei requisiti di conformità.

#
Certificazioni

Stato su 8 standard

SOC 2 Type IINot yet engaged
No third-party audit in progress to date
Nessun documento ad oggi
ISO 27001Not yet engaged
No certification in progress to date
Nessun documento ad oggi
GDPR · DPAOn request
Sub-processing agreement negotiated on a case-by-case basis
Nessun documento ad oggi
HIPAA BAANot yet engaged
No standard BAA available to date
Nessun documento ad oggi
PCI DSS SAQ-DNot yet engaged
No attestation in progress to date
Nessun documento ad oggi
FedRAMP ModerateNot yet engaged
No audit scheduled to date
Nessun documento ad oggi
SecNumCloudNot yet engaged
No ANSSI engagement in progress to date
Nessun documento ad oggi
C5 (Germany)Not yet engaged
No BSI engagement in progress to date
Nessun documento ad oggi
#
Architettura di sicurezza

Difesa in profondità · 7 strati

IN-TRANSIT ENCRYPTION
TLS 1.3, HSTS preload, certificate pinning available, AWS/Azure PrivateLink
AT-REST ENCRYPTION
AES-256 envelope encryption · BYOK via AWS KMS, GCP KMS, HashiCorp Vault, HSM PKCS#11
IDENTITY
SAML 2.0 · OIDC · SCIM 2.0 · Policy-enforced MFA · device fingerprint session binding
AUDIT LOGS
2-year retention · SIEM export (Splunk, Datadog, Elastic, Sumo) · OCSF/JSON format · immutable via S3 Object Lock
PITR
90-day point-in-time recovery · continuous WAL backups · cross-region replication
NETWORK
Cloudflare WAF · per-tenant rate-limiting · IP allowlist · L3/L4/L7 DDoS · VPC peering available
ISOLATION
Dedicated Postgres cluster per project · schema-per-project · kernel-level CPU/RAM isolation (cgroups v2)
#
Processo

Accesso a report dettagliati

§ 01
Request

Email trust@aurabase.cloud with your context (company, sector, requirements).

§ 02
NDA

Mutual NDA signed in 10 minutes via DocuSign (standard template or your own).

§ 03
Access

Direct consultation on our detailed architecture and compliance roadmap.

§ 04
Questions

Technical deep-dive call with our Security Lead within 48 hours.

Astuce
Contatto dedicato: trust@aurabase.cloud · risposta entro 24 ore lavorative.
#
Vulnerabilità

Divulgazione coordinata e ricompensa dei bug

Programma pubblico attivo huntr.dev/aurabase. Taglie che vanno da € 200 a € 10.000 in base alla gravità. Comunicazione coordinata entro 90 giorni. Politica di approdo sicuro per i ricercatori in buona fede.

#
Collegamenti

Risorse complementari

PRONTO A VALUTARE?

Accesso sicuro al portale entro 48 ore.

Invia un'e-mail a trust@aurabase.cloud con i dettagli della tua azienda. NDA reciproco, accesso a report dettagliati sull'architettura e una chiamata con il nostro responsabile della sicurezza.

Nessuna carta di credito richiesta · 500 MB gratuiti · 50.000 MAU