AIARCO logoASC

ASC — Compliance & trust

Last updated: May 2026. Live status page coming with E.4 public launch.

SOC 2 readiness

ASC is in active SOC 2 Type I readiness preparation with audit window targeted Q3 2026. Type II observation period begins immediately after. Infrastructure controls below are technically enforced today; policy documentation lives in /compliance in the parent monorepo (AIARCO MASTER/compliance).

Controls

IDControlStatusNotes
AC-1Tenant isolationEnforcedDB row-level by tenant_id; IAM policies scoped per tenant prefix.
AC-2Bearer-token authEnforcedJWT (15min) + API keys (rotatable).
AU-1Audit trailEnforcedBillingMeter rows immutable; CloudTrail org-wide.
CP-1Backups (RDS)EnforcedAutomated daily, 7-day retention, point-in-time recovery.
SC-1Encryption at restEnforcedS3 SSE-AES256, RDS KMS, EFS KMS, Secrets Manager KMS.
SC-2Encryption in transitEnforcedTLS 1.2+ everywhere; ALB redirects 80→443; EFS in-transit encryption ENABLED.
SI-1Vulnerability scansIn progressDependabot enabled; SBOM generation pending E.4 launch.
IR-1Incident responseDocumentedOn-call rotation + status page (status.asc.aiarco.com — pending).

Sub-processors

  • Amazon Web Services (AWS)
    Compute, storage, networkingus-east-1, eu-central-1 (selectable)
  • Stripe
    Billing & paymentsUS/EU dual
  • GitHub (Microsoft)
    Source control & CIUS
  • Cloudflare
    DNS for asc.aiarco.comGlobal anycast

Data residency

Default region is us-east-1. EU customers can pin tenants to eu-central-1 at provisioning time; cross-region data movement requires explicit opt-in. Customer data is never replicated to non-customer regions.

Questions or to request our trust pack: trust@asc.aiarco.com.