Trust posture
Security without attestation theatre.
Control status, disclosed exactly.
Defense-in-depth spans infrastructure, data, identity, application, monitoring and AI governance, with cryptographic audit trails and zero-trust design (identity-based access live, mTLS in rollout).
Compliance readiness is mapped to SR 11-7 / OCC 2011-12, the EU AI Act and DORA. We never claim an attestation we have not received.
How we build
Security claims are governed like risk claims.
The page is a public trust surface, not a sales badge. A status can be live, in rollout, in build-out, roadmap or not applicable. The distinction is deliberate.
Defense-in-depth, not perimeter trust.
Every request is authenticated independently. Identity-based admin access is live. mTLS is in rollout where service-mesh deployment is required.
Every verdict carries a cryptographic trail.
Input snapshot, kernel and model versions, Governor decision, calibration state and output hash are recorded for replay.
Compliance status is honest, not aspirational.
In progress means building – with artefacts to show. Aligned means defensibly evidenced. We do not claim attestations we have not received.
Critical CVE remediation target: 24 hours.
Scanning covers infrastructure, containers, dependencies and application code. CVE-free status is published only with a verification date, never as a standing claim.
Coordinated disclosure is the default.
Security reports are acknowledged within 24 hours. Remediation targets are Critical 24 h, High 7 d and Medium 30 d.
Compliance register
The register is the status source of truth.
Formal certifications are stated only after receipt. Readiness artefacts can be reviewed under NDA; public language stays below the evidence level, never above it.
| Framework | Status | Public posture |
|---|---|---|
| SOC 2 Type II | In progress | Controls implemented; evidence tooling deployed; independent audit planned. No report issued yet; period and CPA firm published on completion. |
| ISO 27001 | In progress | ISMS underway; gap assessment complete. No certificate issued; target date is not publicly claimed before owner confirmation. |
| GDPR / UK GDPR | In progress | Privacy policy, DPA template, RoPA and DPIA workflow in build-out; data-subject rights operational via founder-direct privacy contact. |
| CCPA / CPRA | In progress | Consumer rights documented and operational via founder-direct privacy contact; we do not sell personal information. |
| DORA EU 2022/2554 | In progress | ICT-risk mapping, incident classification, sub-processor register and TLPT scope; artefact pack in build-out. |
| EU AI Act 2024/1689 | In progress | Per-verdict cryptographic audit trail, human-oversight controls and risk-management file scaffolding; conformity file in build-out. |
| SR 11-7 / OCC 2011-12 | Aligned | Model-risk support mapping for deterministic outputs and vendor-model validation review. Not a regulatory attestation or customer filing. |
| FRTB-IMA | Aligned | Evidence archive supports market-risk model review and record-keeping context. No capital-model approval or certification is claimed. |
| MiCA | Aligned | Digital-asset evidence uses MiCA record-keeping context only. No crypto-asset service authorization, compliance attestation or regulatory endorsement is claimed. |
| NIST CSF 2.0 | Aligned | Controls mapped to Govern / Identify / Protect / Detect / Respond / Recover. Voluntary framework alignment, not certification. |
| Public trust and status pages | Roadmap | Dedicated trust-center and status subdomains are planned. Until then, this page and the NDA trust pack provide supporting trust evidence; this register remains the status source of truth. |
| HIPAA | Roadmap | Not in scope; BAA and PHI controls planned for future healthcare design partners. |
| PCI DSS | Not applicable | No cardholder data on SAA infrastructure; processing delegated to PCI L1 processors. |
| FedRAMP | Not applicable | No federal tenants targeted; re-assessed if a federal design partner enters the pipeline. |
Boundary: Live status reflects operational maturity, not formal attestation. Qualified counterparties can review the SOC 2 readiness report, ISO 27001 gap summary, DORA artefact pack, EU AI Act conformity file, SIG Lite / CAIQ response and SR 11-7 / OCC 2011-12 vendor-model validation support pack under NDA.
Defense-in-depth
Six control domains, labelled by maturity.
Status labels distinguish live controls, tenant-bound capabilities, rollout controls and target cadences. A supported capability is not presented as a current client deployment or formal attestation.
Infrastructure
Multi-AZ cloud and pod-isolation patterns are implemented for the hosted stack. Zero-trust networking is in rollout: identity-based admin access is live; mTLS is a service-mesh capability, enabled where deployed and required for production tenant isolation. Distroless containers, image scanning, WAF and DDoS protection are readiness controls documented in the Trust Pack.
Data
Encryption at rest and TLS in transit are live controls. Customer-managed keys are a supported enterprise / on-prem deployment option, not a claim of current client key custody. Region-locked residency is US / EU today; APAC activates on customer demand. Four-tier classification and PII detection are readiness controls applied at ingestion boundaries.
Identity and access
MFA and role separation are live for administrative access. Enterprise SSO (SAML 2.0 / OIDC), WebAuthn / FIDO2, RBAC / ABAC, managed-vault rotation, immutable identity logs and SIEM export are supported integration controls; activation depends on tenant deployment pattern and customer identity provider.
Application
Security-sensitive changes require review and dependency scanning is part of the build discipline. SAST, DAST, API rate-limiting, field-level authorization, adversarial-input detection and prompt-injection sanitisation are maintained as control objectives with evidence captured in the readiness pack; coverage expands with each production lane.
Monitoring and incident response
Metrics, logs and traces feed operational dashboards and escalation. The NIST SP 800-61-aligned incident-response plan is documented with severity classification and 72-hour breach-notification workflow. BCP / DR plans are documented; quarterly test cadence is the target production cadence after first enterprise tenant, not a historical claim.
AI governance
Verdicts are rule-based and deterministically computed; humans approve release. Low-confidence verdicts auto-escalate through Governor gates. Systematic-error and drift monitoring carry dissent attribution; agent kill-switch controls are documented for production lanes.
Audit and evidence
Replayability is a control, not a brochure line.
The trust pack links security controls, model-risk evidence and verdict replay material without turning readiness into certification language.
| Evidence lane | Public status | Boundary |
|---|---|---|
| Verdict trail | HMAC verdict trail signed per decision; ed25519 hash-chained, append-only ledger. | Replay evidence, not a third-party attestation. |
| Decision integrity | 5 decision-integrity invariants enforced at write time; 7-rule math-to-narrative audit; 1 hash / 1,000 fresh-process repeats. | Internal evidence available under NDA. |
| Infrastructure hardening | 11 / 11 controls PASS, verified 2026-05-27 by least-privilege audit role. | Dated snapshot, not a perpetual CVE-free claim. |
| Evidence archive | S3 Object Lock, SSE-KMS, deny-insecure-transport, lifecycle to deep archive, encrypted EBS and restricted ingress. | 7-year retention pattern for evidence custody. |
| Framework mapping | Evidence archive supports FRTB-IMA, MiCA and SR 11-7 / OCC 2011-12 record-keeping. | Per-framework status is governed by the compliance register above. |
Trust material: Qualified diligence teams receive source screenshots, policy excerpts, evidence hashes and replay instructions under mutual NDA. No report, certificate or customer outcome is implied by access to the pack.
Coordinated disclosure
RFC 9116, founder-direct.
security.txt – public copy · canonical RFC 9116 path: /.well-known/security.txt
Acknowledgment – within 24 hours
Remediation targets – Critical 24 h, High 7 d, Medium 30 d
PGP – public key on request, researcher credit offered
Contact – o.slieptsov@saa-alliance.com
Scope – saa-alliance.com, public subdomains and platform APIs
Languages – en, ru
Security alias – dedicated alias on roadmap; founder-direct intake is live today.
Institutional diligence
Verify the posture before you trust the stack.
Ask for the Trust Pack if you need control mappings, policy artefacts, replay evidence, incident-response material or SR 11-7 / OCC 2011-12 vendor-model validation support. The answer will be evidence-first and claim-bounded.
