Aevus

Security

Built so the controls hold even when the model is wrong

Aevus assumes every agent can make mistakes and every document can be hostile. The platform, not the prompt, decides what happens.

Core guarantees

Four rules the platform enforces

  • Agents never compute money

    Every amount, allocation and waterfall is calculated by tested, deterministic code.

  • People approve what can’t be undone

    Money movement, filings and LP-facing sends wait at a gate for named approvers.

  • Everything is recorded

    Each action writes an append-only record of its inputs, calculation, approver and time.

  • Data stays where it belongs

    Hard tenant isolation, and LP data visible only to the people allowed to see it.

Agent controls

  • Agents act only through typed, permissioned actions
  • Authorization is checked at the tool boundary on every call
  • Content from documents and emails can inform a draft, never trigger an action
  • Every action is idempotent, so retries never double-execute

Data protection

  • Hard tenant isolation enforced in the data layer
  • LP data scoped to authorized parties only
  • Encryption in transit and at rest
  • Credentials held in a vault as short-lived, scoped tokens

Audit and evidence

  • Append-only ledger of every action, input, calculation and approval
  • Exportable evidence for auditors and LP due diligence
  • Policy versions recorded alongside each decision
  • Full history of configuration changes

Reliability

  • Fails closed on stale data or a degraded connector
  • Long workflows run as resumable, durable sagas
  • Partial failures roll back or park for a person
  • Connector health monitored continuously

Trust center

Status of our certifications, policies and security controls.

Compliance6

  • SOC 1 Type II (ISAE 3402)In progress
  • SOC 2 Type IIn progress
  • SOC 2 Type IIIn progress
  • ISO 27001In progress
  • GDPRIn progress
  • EU data residencyIn progress

Legal4

  • Service-level agreementIn progress
  • Terms of serviceIn progress
  • Privacy policyIn progress
  • Data processing agreementIn progress

Corporate security6

  • Incident responseIn progress
  • Quarterly internal assessmentsIn progress
  • Business continuity testingIn progress
  • Single sign-onIn progress
  • Email protectionIn progress
  • Employee security trainingIn progress

Endpoint security2

  • Mobile device managementIn progress
  • Disk encryptionIn progress

Access control4

  • Password securityIn progress
  • Activity loggingIn progress
  • Least-privilege data accessIn progress
  • Quarterly access reviewsIn progress

Network security2

  • Virtual private cloudIn progress
  • Zero-trust accessIn progress

Infrastructure5

  • Infrastructure securityIn progress
  • Separate production environmentIn progress
  • Backups and disaster recoveryIn progress
  • DDoS protectionIn progress
  • Cloud provider hardeningIn progress

App security3

  • Secure development lifecycleIn progress
  • Vulnerability and patch managementIn progress
  • Credential managementIn progress

Data security6

  • Encryption at restIn progress
  • Encryption in transitIn progress
  • Access monitoringIn progress
  • Physical securityIn progress
  • Secure data erasureIn progress
  • Automated backupsIn progress

Product security3

  • Team managementIn progress
  • Audit loggingIn progress
  • Single sign-onIn progress

Policies17

  • Data security policyIn progress
  • Password policyIn progress
  • Bring-your-own-device policyIn progress
  • Data classification policyIn progress
  • Risk management policyIn progress
  • Incident response policyIn progress
  • Encryption policyIn progress
  • Access control policyIn progress
  • Physical security policyIn progress
  • Backup policyIn progress
  • Asset management policyIn progress
  • Development lifecycle policyIn progress
  • Anti-malware policyIn progress
  • Network security policyIn progress
  • Information security policyIn progress
  • Acceptable use policyIn progress
  • Business continuity policyIn progress

Reports4

  • Penetration test reportIn progress
  • Vulnerability assessment reportIn progress
  • SSL Labs gradeIn progress
  • Network diagramIn progress

Sub-processors1

  • Published sub-processor listIn progress

Report a vulnerability or request our security pack

Security reports go straight to the engineers who build the platform.

security@aevus.ai

Walk your security team through it

We’ll take your risk and compliance leads through the controls, with your questionnaire if you have one.