Plain-language description of the platform architecture and security posture behind AEOSOS.
Procurement teams often map vendors to trust criteria. Below is a non-exhaustive alignment map — not an assertion of audit readiness.
| Theme | Our posture |
|---|---|
| Logical access | Separate admin vs tenant surfaces; API keys hashed; optional platform-scoped keys. |
| Change management | Infrastructure-as-code, versioned migrations, peer review for application changes. |
| Logging & monitoring | Structured service logs; a tamper-evident security audit store in which new events are sealed so they cannot be altered after the fact. |
| Encryption | TLS in transit; provider-managed encryption at rest for all bound services. |
| Vendor management | Subprocessor list + notice policy; reliance on our subprocessors' own security programs. |