Institutional due diligence

Security architecture for professional review workflows

This page describes controls, provider responsibilities, access boundaries, data handling, and reviewability for professional client-file workflows.

Aurimen does not claim independent ISO 27001 or SOC 2 certification. Provider programmes do not automatically certify Aurimen.

Section

Security foundations

How protection and reviewability apply to professional client files.

Why security matters

Professional files require proportionate protection and controls that remain reviewable under scrutiny.

  • Files may include ownership structures, transaction narratives, advisor commentary, and documentation prepared for banking or regulatory review.
  • Uncontrolled disclosure could harm clients, firms, and professional reputations.
  • Protection alone is insufficient: security also supports reviewability and defensibility of documented control.
  • The objective is reviewability suitable for due diligence — not promotional claims.

Human accountability

Every professional conclusion remains attributable to a human reviewer. Workflows, documentation, review records, and reasoning trails are structured for traceability. The platform does not assume professional, regulatory, legal, tax, or compliance responsibility. That responsibility remains with advisors, professionals, and firms.

Section

Professional review context

Why firms assess vendors before client information is placed in software.

Why professional firms care

Vendor review is standard practice before client files are placed on external software.

Corporate services firms, CPA firms, family offices, compliance teams, and advisory practices assess technology vendors because client files carry professional and reputational exposure.

  • Client confidentiality — sensitive structural and ownership information must remain controlled.
  • Banking and regulatory reviews — institutions may request documentation and supporting records.
  • Internal governance — partners and risk committees approve tools before firm-wide use.
  • Professional accountability — licensed advisors remain responsible for conclusions and file integrity.
  • Operational continuity — firms need predictable access, retention handling, and incident processes.

Security FAQ

Common questions from compliance, IT, and professional reviewers — answered directly.

Is Aurimen ISO 27001 certified?+

No. Aurimen does not currently claim independent ISO 27001 certification.

Is Aurimen SOC 2 certified?+

No. Aurimen does not currently claim independent SOC 2 certification.

Is Supabase certified?+

Supabase publicly reports ISO/IEC 27001:2022 certification and SOC 2 Type II compliance through its security documentation. Review the current Supabase Trust Center for the latest status.

Does provider certification certify Aurimen?+

No. Provider certifications support infrastructure due diligence but do not transfer application-level assurance or certification to Aurimen.

Who is responsible for security configuration?+

Aurimen configures application-level controls. Customers remain responsible for user governance and internal policies. Provider platform controls remain with the provider.

Who is responsible for row-level security (RLS) policies?+

Aurimen designs and maintains application access patterns and database policies used by the product. RLS works together with application permissions. Customers manage users, roles, firm policies, and lawful processing obligations.

Why does auditability matter?+

Reviewers often need to understand what happened to a file — not only that it was protected. Selected review history, review commentary, and preserved context support later explanation. This is selected professional review workflow history, not a full security audit log.

Does Aurimen train AI models on client data?+

No. Client information is not used to train public AI models. Any future AI-related functionality would be governed by separate product documentation and customer controls.

Where is data physically stored?+

Application data — including workspace records, review history, questionnaire responses, and uploaded files — is stored in Supabase (managed PostgreSQL). Authentication and file storage run through the same Supabase project. Current production configuration uses the eu-west-1 region. Other providers in the processing path (for example email delivery or PDF generation) may process or transit selected data according to their services.

Who can access our workspace data?+

Workspace users access data according to their assigned roles and permissions. Aurimen operational access is limited to authorised support, security, or service needs.

Do you encrypt data?+

TLS protects data in transit. Encryption at rest is provider-managed for Supabase database and storage services. Column-level encryption is not implemented platform-wide.

How long do you keep data?+

Retention is governed by firm policy, applicable legal requirements, and any contractual terms. Workspace-specific procedures can be confirmed during professional or enterprise review.

Can we delete a client file completely?+

Subject to firm policy, applicable legal requirements, and backup cycles. Contact us for workspace-specific procedures.

How do you handle a security incident?+

Security incidents are investigated under internal procedures. Customer notification follows applicable law and contract.

Why security due diligence exists

What reviewers typically examine before approving software for client files.

  • Access controls and role separation
  • Data location and hosting configuration
  • Encryption and credential handling
  • Retention and deletion practices
  • Selected review history and documented reasoning
  • Incident handling and business continuity
  • Provider governance and shared responsibility

Security and professional review readiness

Controls support reviewability without guaranteeing institutional outcomes.

Reviewers commonly assess whether records are controlled, attributable, and explainable. The following characteristics may facilitate professional review — they do not guarantee onboarding, approval, or any particular institutional outcome.

  • Controlled access — visibility aligned to role and matter context.
  • Traceability — selected activity is attributable to users and review context.
  • Reviewability — structured files and preserved review context where supported by the workflow.
  • Documented accountability — professional conclusions remain human-attributed.

Assessment remains with the reviewing institution. Approval decisions are not made by Aurimen.

Security, governance & methodology

Security

Protects information and access — encryption, isolation, and operational controls.

Governance

Preserves accountability — human responsibility, firm policy, and defensible professional use.

Methodology

Structures professional review — workflows, documentation, and preserved reasoning.

Security protects information and access. Governance preserves accountability. Methodology structures professional review.

Section

Infrastructure & provider model

Stack selection, provider assurance, and shared responsibility — without implying provider certification transfers to Aurimen.

Infrastructure Foundation

The platform relies on established infrastructure providers and familiar components that reviewers can map to published vendor documentation.

  • PostgreSQL — primary relational datastore with Row Level Security capabilities.
  • Supabase — managed database, authentication, APIs, storage, and related application services.
  • Application delivery may use Cloudflare and cloud hosting layers, depending on deployment configuration.
  • Other processing services (for example email and PDF generation) may participate in selected workflows.

Why this architecture

Widely understood

Components are commonly reviewed in enterprise and professional-firm security assessments.

Published documentation

Major providers publish security documentation that can support infrastructure due diligence.

Describable controls

Architecture, access patterns, and data lifecycle can be explained for professional review.

Shared responsibility

Provider infrastructure assurance remains distinct from Aurimen application governance.

Why Supabase

Institutional rationale for the datastore and application services layer.

Supabase is used because it combines managed PostgreSQL, authentication, storage, and application services within one platform supported by publicly available security documentation.

  • Managed PostgreSQL with Row Level Security capabilities.
  • Authentication, APIs, and storage within the same platform.
  • Published provider documentation supporting infrastructure due diligence.
  • Established operational practices rather than opaque proprietary infrastructure.

Provider Security Programs

Infrastructure providers may maintain independent security and compliance programmes.

Aurimen is not ISO certified. Aurimen is not SOC 2 certified.

Supabase publicly reports, through its published security documentation:

  • ISO/IEC 27001:2022
  • SOC 2 Type II

Provider certifications support infrastructure due diligence but do not transfer application-level assurance or certification to Aurimen. Provider documentation may be reviewed through the Supabase Trust Center or under the applicable plan.

Provider certification

Relates to the vendor's infrastructure and managed services — attestations published by the provider.

Application governance

Relates to application configuration, RLS alignment, workspace permissions, secrets, operational procedures, and customer user governance.

Deterministic workflow principle

Designed to

Structure professional review workflows, organise information, and preserve documented reasoning for professional review.

Not designed to

Make professional decisions, replace professional judgement, or issue legal or tax conclusions.

Where data lives

Hosted infrastructure

Application and client data are stored in Supabase (managed PostgreSQL), including workspace records, review history, and uploaded files. Selected workflow services may process data in transit.

Separation of environments

Production, staging, and development contexts remain logically separated.

No sale of client data

Information is processed to deliver the service — not sold for unrelated purposes.

Traceability

Selected processing activities remain attributable to workspace, role, and matter context.

Regional deployment options

  • Current production hosting uses the configured Supabase project region (eu-west-1).
  • Alternative deployment arrangements may be reviewed separately for enterprise requirements and are not part of the standard public plan.
  • Jurisdiction-specific residency expectations should be confirmed against the current configuration during professional or enterprise review.

Section

Access control & isolation

How access boundaries and workspace separation support defensible professional use.

Why Row Level Security matters

For non-technical partners, corporate services professionals, and risk officers reviewing access control.

  • Matter-level isolation — access is restricted to the client files and matters users are authorised to work on.
  • Workspace-level isolation — one firm's files remain separated from another firm's environment in the standard model.
  • Role-based access — access is limited through assigned roles and permissions, not broad administrative visibility by default.
  • Database-level rules reduce the risk that a user retrieves records outside their permitted scope.
  • Access rules can be described and reviewed during institutional or compliance assessment.

Row Level Security is a database mechanism that enforces record-level boundaries, working together with application permissions. It supports controlled access — it does not replace firm governance or professional judgement.

Auditability

Security protects information. Selected review history helps explain what happened to it.

Aurimen records selected professional review workflow events — not a full security audit log of every access or authentication event. What is preserved supports later explanation of review activity within controlled boundaries.

  • Who reviewed a file — review activity preserved within professional review workflow context.
  • Who commented — commentary associated with the reviewer and review stage.
  • Review history — prior review cycles and commentary where retained by the workflow.
  • Traceability — links between inputs, review steps, and documented conclusions where recorded.
  • Accountability — professional judgement remains human-attributed.

No specific logging standard or certification is claimed on this page. Records such as certified archives and report snapshots are designed to be preserved; not all history is described as immutable.

Supabase & PostgreSQL

Technical summary for IT reviewers and compliance teams.

  • PostgreSQL Row Level Security (RLS) aligns row-level access with application permissions, where configured.
  • Access is controlled through database policies and application permissions working together.
  • Role-based access patterns are applied at the application and workspace layers.
  • Workspace isolation limits visibility between firms in the standard product model.
  • Service-role credentials must remain server-side — they must not be exposed to the client.
  • Security depends on provider controls and correct application configuration under shared responsibility.

Shared responsibility model

Provider

Infrastructure, managed platform operations, baseline encryption, availability practices, and provider documentation.

Aurimen

Application configuration, access-control design, workspace permissions, security procedures, and application-level operation.

Customer / Professional Firm

User administration, internal policies, lawful basis, retention instructions, appropriate use, professional review procedures, client advice, professional judgement, licensing, and regulatory obligations.

Authentication

Identity verification

Users authenticate with password credentials before accessing workspace features.

Session management

Sessions are managed according to provider and configured authentication policies.

Multi-factor authentication

Authenticator-based (TOTP) MFA is available and may be configured for workspace users. It is not described as mandatory on this page.

Account recovery

Password recovery flows balance accessibility with identity verification.

Access control

  • Role-based access within a workspace.
  • Workspace-level boundaries and matter-level access where configured.
  • RLS-aligned patterns at the datastore layer, working with application permissions.
  • No cross-workspace visibility in the standard model.
  • Administrative and service-role access restricted to appropriate operational paths.
  • Client-facing users access only permitted matters and workspaces.

Encryption

In transit

TLS protects data between clients and services.

At rest

Provider-managed encryption applies to managed database and storage.

Secrets

Stored outside application source code via environment configuration.

Server-side credentials

Privileged credentials are restricted to server-side only.

Column-level encryption

Not implemented platform-wide. May be evaluated for specific use cases where required.

Workspace isolation

Logical separation between firms and matters.

  • Each workspace is a firm-level boundary for users and matters.
  • Separation is logical and policy-based within a shared platform — not physical isolation.
  • Cross-workspace access is not part of the standard model; authorised operational or administrative paths may exist separately.
  • Supports multi-firm operation without commingling unrelated client files in the standard product model.

Section

Data lifecycle & retention

How information moves through controlled stages from submission to deletion.

Data lifecycle

  1. Submission

    Client or advisor inputs

  2. Processing

    Structured for review

  3. Controlled access

    Role-gated views

  4. Secure storage

    Database & files

  5. Archive

    Preserved outputs where supported

  6. Retention

    Per firm policy

  7. Deletion

    When applicable

Defined records or review outputs may be preserved for later review where supported by the configured workflow (for example certified archives and preserved report snapshots). Not all records are archived. Information is processed for the professional review workflow requested — not for unrelated analytics, model training, or resale.

Retention

  • Retention is governed by firm policy, applicable law, and any contractual terms.
  • Preserved review outputs and certified archives may remain available where the workflow supports them.
  • Firms define internal retention aligned with regulatory and client obligations.

Deletion

  • Evaluated against firm policy and applicable legal requirements.
  • Active-system deletion is subject to backup rotation windows.
  • Procedures may be documented for enterprise review on request. Guaranteed deletion timing is not stated on this page.

Section

Operational resilience

Availability, incident handling, and recovery practices.

Business continuity

Availability

Operated with reasonable efforts to maintain availability. Contractual commitments, if any, are defined separately.

Incident handling

Security incidents are investigated under internal procedures. This page does not describe a formal certified incident programme.

Notification

Customers may be notified when required by applicable law and contract.

Dependencies

Providers are selected with operational and security risk in mind.

Backups

  • Managed provider backup capabilities, where enabled for the environment.
  • Intended for disaster recovery — not routine undelete.
  • Retention follows provider and environment configuration. RTO and RPO commitments are not stated on this page.

Section

Data protection & lawful processing

Jurisdiction-aware considerations for firms operating across multiple regions.

Data protection & lawful processing

Jurisdiction-aware compliance considerations apply depending on where the firm and its clients operate. Where the GDPR applies, lawful processing principles are relevant. Other frameworks may apply in parallel.

Purpose limitation

Processing for the service — not unrelated purposes.

Data minimization

Collect what professional review requires.

Rights requests

Handled in coordination with the controlling firm where applicable.

Sub-processors

Described on request where information is maintained.

This summary is informational — not a Data Processing Agreement, legal advice, or jurisdiction-specific compliance guarantee.

Section

Security evidence for review

Documentation that may be provided under confidentiality for professional or enterprise assessment.

Security evidence on request

For professional or enterprise review, selected documentation may be prepared or provided under confidentiality. This page does not promise penetration-test reports, Aurimen audit reports, or Aurimen certification documents unless formally offered.

  • Architecture overview
  • Access-control overview
  • Workspace-separation explanation
  • RLS explanation
  • Data-flow summary
  • Retention and deletion summary
  • Provider references
  • Subprocessor information, where maintained

Important

This page summarises Aurimen's current security architecture and operating principles for informational due diligence. It is not a binding security appendix, penetration-test report, audit opinion, certification, or substitute for executed agreements and current provider documentation. Specific enterprise commitments are governed only by executed contractual documents. Provider compliance programmes do not transfer to Aurimen. No guarantee of compliance with any specific law or framework is made on this page.

Aurimen — Security overview

Designed to support structured professional review workflows and recurring client files. Availability varies by workspace plan.