AIARCOAIARCOASC
Trust & Compliance

Sovereign by design. Audited by default.

Workloads run in your isolated tenant under scoped execution roles. Every API call lands in the control-plane audit log. Last updated May 2026.

SOC 2 Type II
in progress
Encryption
Envelope + TLS 1.2+
Audit
Append-only
RPO / RTO
≤24h / ≤4h

SOC 2 readiness

ASC is in active SOC 2 Type I readiness with audit window targeted Q3 2026. Type II observation period begins immediately after. Infrastructure controls below are technically enforced today.

Controls

IDControlStatusNotes
AC-1Tenant isolationEnforcedDB row-level by tenant_id; access policies scoped per tenant prefix.
AC-2Bearer-token authEnforcedJWT (15min) + API keys (rotatable).
AU-1Audit trailEnforcedBilling meter rows immutable; control-plane audit log append-only.
CP-1BackupsEnforcedAutomated daily, 7-day retention, point-in-time recovery.
SC-1Encryption at restEnforcedAll persisted data envelope-encrypted; per-tenant data keys.
SC-2Encryption in transitEnforcedTLS 1.2+ everywhere; HTTP redirects to HTTPS; in-transit encryption on all storage volumes.
SI-1Vulnerability scansIn progressDependabot enabled; SBOM generation in roadmap.
IR-1Incident responseDocumentedOn-call rotation + status page (planned).

Sub-processors

  • Hyperscaler cloud provider
    Compute, storage, networkingus-east, eu-central, ap-southeast (selectable)
  • Stripe
    Billing & paymentsUS/EU dual
  • GitHub (Microsoft)
    Source control & CIUS
  • Anycast DNS provider
    DNS for asc.aiarco.comGlobal anycast

Data residency

Default region is us-east. EU customers can pin tenants to eu-central; cross-region movement requires explicit opt-in. Customer data is never replicated to non-customer regions.

Trust pack

Penetration test summaries, SOC 2 progress, and questionnaire responses available under NDA.

trust@asc.aiarco.com