Trust & Security

Security you can verify, not a badge wall

We're pre-launch. Instead of a page of logos we haven't earned, here's exactly what's true in the code today — and what we're building next before we ask you to put real customer data through us.

In the code today

What's true right now

Every line below is a fact about the running platform, not a plan.

Encryption in transit & at rest

TLS 1.2+ for everything that moves, AES-256 for everything that sits.

Role-based access control

Owner → Admin → Manager → Agent — everyone sees exactly what their role needs, nothing more.

Session rotation & optional MFA

Sessions rotate on login. Multi-factor authentication is available to every organisation that wants it on.

Hard tenant isolation

Every query is scoped to your organisation automatically, at the database layer — not a setting someone could leave off.

Immutable audit log

Every ticket action and every partner action is recorded in a log that can't be edited or deleted after the fact.

Per-organisation data retention

Retention rules are set per organisation to match your own GDPR and data-residency obligations — not one blanket policy for everyone.

Scoped integration access

Every connected app gets short-lived tokens and its own rate limit, so a misconfigured integration can't become a security gap.

Rate-limited approval links

No-login approval links are rate-limited and OTP-verified, so they can't be brute-forced or guessed.

No black boxes

One tenant never sees another's data

Every ticket, every customer record, every attachment belongs to one organisation — and the platform enforces that on every single database query automatically. It isn't a checkbox an engineer could forget or a policy that relies on good behaviour. One organisation's data cannot appear in another's view.

Not yet true — and we're not going to pretend otherwise

What we're building next

Before we ask a large customer to put real, sensitive data through Auradesk, this is what still has to be true.

An independent penetration test — not yet commissioned.

SOC 2 Type II — not yet started. On the roadmap before we pursue larger accounts.

A published hosting region and sub-processor list.

A public status and uptime page.

CCPA rights language alongside our existing GDPR-based retention rules.

Have a security question we didn't answer?

Ask us directly — including anything on the "not yet" list above. We'd rather tell you where we stand than have you guess.