Trust & Security
Security you can verify, not a badge wall
We're pre-launch. Instead of a page of logos we haven't earned, here's exactly what's true in the code today — and what we're building next before we ask you to put real customer data through us.
In the code today
What's true right now
Every line below is a fact about the running platform, not a plan.
Encryption in transit & at rest
TLS 1.2+ for everything that moves, AES-256 for everything that sits.
Role-based access control
Owner → Admin → Manager → Agent — everyone sees exactly what their role needs, nothing more.
Session rotation & optional MFA
Sessions rotate on login. Multi-factor authentication is available to every organisation that wants it on.
Hard tenant isolation
Every query is scoped to your organisation automatically, at the database layer — not a setting someone could leave off.
Immutable audit log
Every ticket action and every partner action is recorded in a log that can't be edited or deleted after the fact.
Per-organisation data retention
Retention rules are set per organisation to match your own GDPR and data-residency obligations — not one blanket policy for everyone.
Scoped integration access
Every connected app gets short-lived tokens and its own rate limit, so a misconfigured integration can't become a security gap.
Rate-limited approval links
No-login approval links are rate-limited and OTP-verified, so they can't be brute-forced or guessed.
No black boxes
One tenant never sees another's data
Every ticket, every customer record, every attachment belongs to one organisation — and the platform enforces that on every single database query automatically. It isn't a checkbox an engineer could forget or a policy that relies on good behaviour. One organisation's data cannot appear in another's view.
Not yet true — and we're not going to pretend otherwise
What we're building next
Before we ask a large customer to put real, sensitive data through Auradesk, this is what still has to be true.
An independent penetration test — not yet commissioned.
SOC 2 Type II — not yet started. On the roadmap before we pursue larger accounts.
A published hosting region and sub-processor list.
A public status and uptime page.
CCPA rights language alongside our existing GDPR-based retention rules.
Have a security question we didn't answer?
Ask us directly — including anything on the "not yet" list above. We'd rather tell you where we stand than have you guess.