Trust posture

Security without attestation theatre.

Control status, disclosed exactly.

Defense-in-depth spans infrastructure, data, identity, application, monitoring and AI governance, with cryptographic audit trails and zero-trust design (identity-based access live, mTLS in rollout).

Compliance readiness is mapped to SR 11-7 / OCC 2011-12, the EU AI Act and DORA. We never claim an attestation we have not received.

11 / 11infrastructure controls PASS, verified 2026-05-27
SOC 2Type II in progress, no report issued
US / EUdata residency today, APAC on demand
24 hcritical CVE remediation target
RFC 9116coordinated disclosure via security.txt

How we build

Security claims are governed like risk claims.

The page is a public trust surface, not a sales badge. A status can be live, in rollout, in build-out, roadmap or not applicable. The distinction is deliberate.

01

Defense-in-depth, not perimeter trust.

Every request is authenticated independently. Identity-based admin access is live. mTLS is in rollout where service-mesh deployment is required.

02

Every verdict carries a cryptographic trail.

Input snapshot, kernel and model versions, Governor decision, calibration state and output hash are recorded for replay.

03

Compliance status is honest, not aspirational.

In progress means building – with artefacts to show. Aligned means defensibly evidenced. We do not claim attestations we have not received.

04

Critical CVE remediation target: 24 hours.

Scanning covers infrastructure, containers, dependencies and application code. CVE-free status is published only with a verification date, never as a standing claim.

05

Coordinated disclosure is the default.

Security reports are acknowledged within 24 hours. Remediation targets are Critical 24 h, High 7 d and Medium 30 d.

Compliance register

The register is the status source of truth.

Formal certifications are stated only after receipt. Readiness artefacts can be reviewed under NDA; public language stays below the evidence level, never above it.

FrameworkStatusPublic posture
SOC 2 Type IIIn progressControls implemented; evidence tooling deployed; independent audit planned. No report issued yet; period and CPA firm published on completion.
ISO 27001In progressISMS underway; gap assessment complete. No certificate issued; target date is not publicly claimed before owner confirmation.
GDPR / UK GDPRIn progressPrivacy policy, DPA template, RoPA and DPIA workflow in build-out; data-subject rights operational via founder-direct privacy contact.
CCPA / CPRAIn progressConsumer rights documented and operational via founder-direct privacy contact; we do not sell personal information.
DORA EU 2022/2554In progressICT-risk mapping, incident classification, sub-processor register and TLPT scope; artefact pack in build-out.
EU AI Act 2024/1689In progressPer-verdict cryptographic audit trail, human-oversight controls and risk-management file scaffolding; conformity file in build-out.
SR 11-7 / OCC 2011-12AlignedModel-risk support mapping for deterministic outputs and vendor-model validation review. Not a regulatory attestation or customer filing.
FRTB-IMAAlignedEvidence archive supports market-risk model review and record-keeping context. No capital-model approval or certification is claimed.
MiCAAlignedDigital-asset evidence uses MiCA record-keeping context only. No crypto-asset service authorization, compliance attestation or regulatory endorsement is claimed.
NIST CSF 2.0AlignedControls mapped to Govern / Identify / Protect / Detect / Respond / Recover. Voluntary framework alignment, not certification.
Public trust and status pagesRoadmapDedicated trust-center and status subdomains are planned. Until then, this page and the NDA trust pack provide supporting trust evidence; this register remains the status source of truth.
HIPAARoadmapNot in scope; BAA and PHI controls planned for future healthcare design partners.
PCI DSSNot applicableNo cardholder data on SAA infrastructure; processing delegated to PCI L1 processors.
FedRAMPNot applicableNo federal tenants targeted; re-assessed if a federal design partner enters the pipeline.

Boundary: Live status reflects operational maturity, not formal attestation. Qualified counterparties can review the SOC 2 readiness report, ISO 27001 gap summary, DORA artefact pack, EU AI Act conformity file, SIG Lite / CAIQ response and SR 11-7 / OCC 2011-12 vendor-model validation support pack under NDA.

Defense-in-depth

Six control domains, labelled by maturity.

Status labels distinguish live controls, tenant-bound capabilities, rollout controls and target cadences. A supported capability is not presented as a current client deployment or formal attestation.

01 Infrastructure – implemented / rollout

Infrastructure

Multi-AZ cloud and pod-isolation patterns are implemented for the hosted stack. Zero-trust networking is in rollout: identity-based admin access is live; mTLS is a service-mesh capability, enabled where deployed and required for production tenant isolation. Distroless containers, image scanning, WAF and DDoS protection are readiness controls documented in the Trust Pack.

02 Data – live / customer-bound

Data

Encryption at rest and TLS in transit are live controls. Customer-managed keys are a supported enterprise / on-prem deployment option, not a claim of current client key custody. Region-locked residency is US / EU today; APAC activates on customer demand. Four-tier classification and PII detection are readiness controls applied at ingestion boundaries.

03 Identity and access – live / integration-bound

Identity and access

MFA and role separation are live for administrative access. Enterprise SSO (SAML 2.0 / OIDC), WebAuthn / FIDO2, RBAC / ABAC, managed-vault rotation, immutable identity logs and SIEM export are supported integration controls; activation depends on tenant deployment pattern and customer identity provider.

04 Application – live / build-out

Application

Security-sensitive changes require review and dependency scanning is part of the build discipline. SAST, DAST, API rate-limiting, field-level authorization, adversarial-input detection and prompt-injection sanitisation are maintained as control objectives with evidence captured in the readiness pack; coverage expands with each production lane.

05 Monitoring and IR – documented / cadence pending

Monitoring and incident response

Metrics, logs and traces feed operational dashboards and escalation. The NIST SP 800-61-aligned incident-response plan is documented with severity classification and 72-hour breach-notification workflow. BCP / DR plans are documented; quarterly test cadence is the target production cadence after first enterprise tenant, not a historical claim.

06 AI governance – live / Governor-bound

AI governance

Verdicts are rule-based and deterministically computed; humans approve release. Low-confidence verdicts auto-escalate through Governor gates. Systematic-error and drift monitoring carry dissent attribution; agent kill-switch controls are documented for production lanes.

Audit and evidence

Replayability is a control, not a brochure line.

The trust pack links security controls, model-risk evidence and verdict replay material without turning readiness into certification language.

Evidence lanePublic statusBoundary
Verdict trailHMAC verdict trail signed per decision; ed25519 hash-chained, append-only ledger.Replay evidence, not a third-party attestation.
Decision integrity5 decision-integrity invariants enforced at write time; 7-rule math-to-narrative audit; 1 hash / 1,000 fresh-process repeats.Internal evidence available under NDA.
Infrastructure hardening11 / 11 controls PASS, verified 2026-05-27 by least-privilege audit role.Dated snapshot, not a perpetual CVE-free claim.
Evidence archiveS3 Object Lock, SSE-KMS, deny-insecure-transport, lifecycle to deep archive, encrypted EBS and restricted ingress.7-year retention pattern for evidence custody.
Framework mappingEvidence archive supports FRTB-IMA, MiCA and SR 11-7 / OCC 2011-12 record-keeping.Per-framework status is governed by the compliance register above.

Trust material: Qualified diligence teams receive source screenshots, policy excerpts, evidence hashes and replay instructions under mutual NDA. No report, certificate or customer outcome is implied by access to the pack.

Coordinated disclosure

RFC 9116, founder-direct.

security.txtpublic copy · canonical RFC 9116 path: /.well-known/security.txt

Acknowledgment – within 24 hours

Remediation targets – Critical 24 h, High 7 d, Medium 30 d

PGP – public key on request, researcher credit offered

Contacto.slieptsov@saa-alliance.com

Scope – saa-alliance.com, public subdomains and platform APIs

Languages – en, ru

Security alias – dedicated alias on roadmap; founder-direct intake is live today.

Institutional diligence

Verify the posture before you trust the stack.

Ask for the Trust Pack if you need control mappings, policy artefacts, replay evidence, incident-response material or SR 11-7 / OCC 2011-12 vendor-model validation support. The answer will be evidence-first and claim-bounded.

Verify this page: Data room · Methodology
Scroll to Top
SAA Capital Models
Select Your Analytics Dashboard
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
📊
Investment Dashboard
Comprehensive stock analysis with technical and fundamental indicators. Generate detailed reports with charts and forecasts.
  • 53 US stocks analysis
  • SEC EDGAR integration
  • HTML reports generation
  • EN/RU language support
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
💧
Liquidity Positioner
Cross-platform personal finance office. Unified budgeting, cash-flow forecasts and AI guidance for private investors and families.
  • Portfolio & liability tracking across assets
  • Budgeting with recurring reminders
  • Cash-flow forecasts & what-if scenarios
  • Premium AI insights, open banking sync
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
⚖️
Risk Analyzer
Institutional portfolio risk management platform. Advanced VaR, stress testing, and tail risk analysis.
  • VaR/CVaR (Historical, Parametric, MC)
  • Stress testing & PCA analysis
  • 10k-100k Monte Carlo simulations
  • Backtesting & validation
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
📰
News Analytics Portal
Bloomberg-style news analysis platform. AI-powered processing, sentiment tracking, sector impact, and professional digests.
  • 20+ sectors coverage
  • AI sentiment analysis (GPT-4, DeepSeek)
  • Multi-language support (EN/RU)
  • Telegram integration
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
Crypto Analytics Portal
Comprehensive digital asset intelligence platform with real-time market data, institutional-grade metrics, and advanced analysis tools.
  • Real-time market data & price tracking
  • On-chain metrics & network analytics
  • Security & regulatory compliance scores
  • Institutional research reports
🟢 Available
SAA LEARNING INTELLIGENCE
Premium Research & Learning Intelligence
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
🎓
SAA LEARNING INTELLIGENCE
Comprehensive learning platform with courses, methodologies, and training materials. Advanced research tools and educational resources for professional development.
  • Interactive courses & tutorials
  • Research methodologies
  • Professional training programs
  • Premium learning intelligence
🟢 Available
SAA LABS
AI Models, Forecasts, Simulations
Status: Active Development (Private Testing)
Data: Live and simulated data
Output: Subject to refinement
🤖
AI Trader
Institutional-Grade Intraday Crypto Trading Platform. Professional-grade algorithmic trading platform designed for institutional and advanced retail traders. Combines real-time market data processing, AI-powered market analysis, and sophisticated risk management.
  • Real-time market data processing
  • AI-powered market analysis
  • Sophisticated risk management
  • Systematic trading capabilities
🟢 Available
Status: Live Analytics (Production)
Mode: Read-only analytical execution
Execution & trading: Restricted
🌐
Global Risk Intelligence Platform
Institutional-Grade Risk Analytics & Regulatory Compliance. The world's most comprehensive, auditable, and regulator-grade risk intelligence platform, rivaling Bloomberg Risk / MSCI RiskManager / Ortec.
  • Institutional-grade risk analytics
  • Regulatory compliance tools
  • Comprehensive risk intelligence
  • G-SIBs & multinational banks ready
🟢 Available
Status: Active Development (Private Testing)
Data: Live and simulated data
Output: Subject to refinement
🔄
ARIN Platform
Autonomous Risk Intelligence Network. Institutional-Grade Multi-Agent System for Predictive Risk Management. A comprehensive risk management system based on Agentic AI, which uses 6 specialized agents to analyze credit, market, operational, liquidity, regulatory, and systemic risks.
  • 6 specialized AI agents
  • Multi-dimensional risk analysis
  • Predictive risk management
  • Credit, Market, Operational, Liquidity, Regulatory, Systemic
🟢 Available