Security & Compliance

Sovereign-grade security. Honestly disclosed.

Defense-in-depth across six control domains — infrastructure, data, identity, application, monitoring, and AI governance — with a cryptographic audit trail, zero-trust networking, and continuous compliance monitoring aligned with Fed/OCC/FDIC SR 26-2, the EU AI Act, and DORA. Our compliance status is conservative by design: we never claim an attestation we have not received.

How we build, not what we sell

01

Defense-in-depth, not perimeter trust.

Every request authenticated independently; mTLS service-to-service; identity-based admin access; no implicit network trust.

02

Every AI verdict carries a cryptographic audit trail.

Input-snapshot hash · kernel & model versions · governor decisions · calibration state · output hash — aligned with SR 26-2 and EU AI Act Article 12. Any historical verdict replays bit-for-bit.

03

Compliance status is honest, not aspirational.

«In progress» means building — not vapourware. «Aligned» means defensibly evidenced. We do not claim attestations we have not received. The posture below is conservative by design.

04

Critical CVEs patched in 24 hours.

Continuous scanning across infrastructure, containers, dependencies, and application code, tracked in a central register. CVE-free status is published only with a verification date — never as a standing claim.

05

Coordinated disclosure is the default.

Security reports acknowledged within 24 hours; a clear remediation timeline — Critical 24 h · High 7 d · Medium 30 d.

Compliance posture

We do not claim an attestation we have not received.

SOC 2 Type IIIn progressControls implemented; evidence tooling deployed; independent audit scheduled. No report issued yet — period & CPA firm published on completion.
ISO 27001In progressISMS underway; gap assessment complete; target Q3 2026. No certificate issued.
GDPR / UK GDPRIn progressPrivacy policy, DPA template, RoPA, DPIA workflow in build-out; data-subject rights operational via founder-direct privacy contact.
CCPA / CPRAIn progressConsumer rights documented and operational via founder-direct privacy contact; we do not sell personal information.
DORA · EU 2022/2554In progressICT-risk mapping, incident classification, sub-processor register, TLPT scope; artefact pack in build-out.
EU AI Act · 2024/1689In progressPer-verdict cryptographic audit trail, human-oversight controls, risk-management file scaffolding; conformity file in build-out.
NIST CSF 2.0AlignedControls mapped to Govern / Identify / Protect / Detect / Respond / Recover. Voluntary framework — alignment, not certification.
Public trust & status pagesRoadmapDedicated trust-center and status subdomains are planned. Until then, this page and the NDA trust pack are the single source of truth.
HIPAARoadmapNot in scope; BAA + PHI controls planned for future healthcare design partners.
PCI DSSNot applicableNo cardholder data on SAA infrastructure; processing delegated to PCI L1 processors.
FedRAMPNot applicableNo federal tenants targeted; re-assessed if a federal design partner enters the pipeline.

Live status reflects operational maturity, not formal attestation. Qualified counterparties obtain the SOC 2 readiness report, ISO 27001 gap summary, DORA artefact pack, EU AI Act conformity file, SIG Lite / CAIQ response, and the SR 26-2 third-party model-validation pack under NDA.

Defense-in-depth · six control domains

01 · Infrastructure

Infrastructure

Multi-AZ cloud with Kubernetes pod isolation and no public data-plane exposure. Zero-trust networking — mTLS and identity-based admin access. Distroless containers with image scanning in CI; edge WAF and DDoS protection.

02 · Data

Data

AES-256-GCM at rest with customer-managed keys; TLS 1.3 only in transit; column-level PII encryption. Region-locked residency — US / EU today, APAC on customer demand, no cross-region by default; four-tier classification with PII detection on ingestion.

03 · Identity & access

Identity & access

SSO (SAML 2.0 / OIDC) with MFA enforced (TOTP / WebAuthn / FIDO2). RBAC and ABAC; secrets in a managed vault with rotation; an immutable identity audit log — 365 days, tamper-evident hash chain, SIEM export.

04 · Application

Application

OWASP SAMM-aligned SDLC with mandatory review for security-sensitive changes. SAST, DAST and dependency scanning in CI; API rate-limiting and field-level authorization; adversarial-input detection and prompt-injection sanitisation on all LLM lanes.

05 · Monitoring & IR

Monitoring & incident response

Centralized metrics, logs and traces with security dashboards and operational escalation. NIST SP 800-61-aligned incident-response plan with severity classification and 72-hour breach notification; BCP / DR testing on a quarterly cadence.

06 · AI governance

AI governance · Responsible AI

Verdicts are rule-based and deterministically computed; humans approve release. Low-confidence verdicts auto-escalate; systematic-error and drift monitoring with dissent attribution; instant agent kill-switch.

Audit & evidence

Every verdict is cryptographically bound and replayable.

HMAC verdict trail signed per decision; ed25519 hash-chained, append-only ledger.

5 decision-integrity invariants enforced at write time; 7-rule math-to-narrative audit; 1 hash / 1,000 fresh-process repeats — bit-for-bit determinism.

Infrastructure hardening — 11 / 11 controls PASSverified 2026-05-27 · least-privilege audit role
S3 Object Lock (evidence archive — 7-year retention), SSE-KMS, deny-insecure-transport, lifecycle to deep archive, encrypted EBS, restricted ingress.

The evidence archive underpins alignment with FRTB-IMA · MiCA · SR 26-2 record-keeping — per-framework status in the register above (single source of truth).

Coordinated disclosure · RFC 9116

security.txt/.well-known/security.txt
Contacto.slieptsov@saa-alliance.com (founder-direct; dedicated security alias on the roadmap)
Acknowledgment — within 24 hours
Remediation — Critical 24 h · High 7 d · Medium 30 d
PGP — public key on request · researcher credit offered
Scope — saa-alliance.com · *.saa-alliance.com · platform APIs
Languages — en, ru

Math first · Agents second · Governor always · Audit forever

© 2026 Scientific Analytics Alliance Inc. · Sovereign Risk Infrastructure Privacy· Terms· Security NVIDIA Inception Program Member
Прокрутить вверх
SAA Capital Models
Select Your Analytics Dashboard
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
📊
Investment Dashboard
Comprehensive stock analysis with technical and fundamental indicators. Generate detailed reports with charts and forecasts.
  • 53 US stocks analysis
  • SEC EDGAR integration
  • HTML reports generation
  • EN/RU language support
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
💧
Liquidity Positioner
Cross-platform personal finance office. Unified budgeting, cash-flow forecasts and AI guidance for private investors and families.
  • Portfolio & liability tracking across assets
  • Budgeting with recurring reminders
  • Cash-flow forecasts & what-if scenarios
  • Premium AI insights, open banking sync
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
⚖️
Risk Analyzer
Institutional portfolio risk management platform. Advanced VaR, stress testing, and tail risk analysis.
  • VaR/CVaR (Historical, Parametric, MC)
  • Stress testing & PCA analysis
  • 10k-100k Monte Carlo simulations
  • Backtesting & validation
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
📰
News Analytics Portal
Bloomberg-style news analysis platform. AI-powered processing, sentiment tracking, sector impact, and professional digests.
  • 20+ sectors coverage
  • AI sentiment analysis (GPT-4, DeepSeek)
  • Multi-language support (EN/RU)
  • Telegram integration
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
Crypto Analytics Portal
Comprehensive digital asset intelligence platform with real-time market data, institutional-grade metrics, and advanced analysis tools.
  • Real-time market data & price tracking
  • On-chain metrics & network analytics
  • Security & regulatory compliance scores
  • Institutional research reports
🟢 Available
SAA LEARNING INTELLIGENCE
Premium Research & Learning Intelligence
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
🎓
SAA LEARNING INTELLIGENCE
Comprehensive learning platform with courses, methodologies, and training materials. Advanced research tools and educational resources for professional development.
  • Interactive courses & tutorials
  • Research methodologies
  • Professional training programs
  • Premium learning intelligence
🟢 Available
SAA LABS
AI Models, Forecasts, Simulations
Status: Active Development (Private Testing)
Data: Live and simulated data
Output: Subject to refinement
🤖
AI Trader
Institutional-Grade Intraday Crypto Trading Platform. Professional-grade algorithmic trading platform designed for institutional and advanced retail traders. Combines real-time market data processing, AI-powered market analysis, and sophisticated risk management.
  • Real-time market data processing
  • AI-powered market analysis
  • Sophisticated risk management
  • Systematic trading capabilities
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
🌐
Global Risk Intelligence Platform
Institutional-Grade Risk Analytics & Regulatory Compliance. The world's most comprehensive, auditable, and regulator-grade risk intelligence platform, rivaling Bloomberg Risk / MSCI RiskManager / Ortec.
  • Institutional-grade risk analytics
  • Regulatory compliance tools
  • Comprehensive risk intelligence
  • G-SIBs & multinational banks ready
🟢 Available
Status: Active Development (Private Testing)
Data: Live and simulated data
Output: Subject to refinement
🔄
ARIN Platform
Autonomous Risk Intelligence Network. Institutional-Grade Multi-Agent System for Predictive Risk Management. A comprehensive risk management system based on Agentic AI, which uses 6 specialized agents to analyze credit, market, operational, liquidity, regulatory, and systemic risks.
  • 6 specialized AI agents
  • Multi-dimensional risk analysis
  • Predictive risk management
  • Credit, Market, Operational, Liquidity, Regulatory, Systemic
🟢 Available