SECURITY & TRUST CENTER

Built for Record Integrity
and Legal Defensibility

AegisIQ's security posture, infrastructure controls, compliance roadmap, and data governance practices for enterprise customers.

Contact Security Team
Infrastructure

Hosting & Data Architecture

AegisIQ is built on enterprise-grade cloud infrastructure with entity-level data isolation at every layer.

Application Hosting

Deployed on Netlify — SOC 2 Type II certified CDN with global edge network and automatic HTTPS enforcement.

Database

Neon PostgreSQL — SOC 2 Type II, GDPR-ready. Continuous backup with point-in-time recovery. Entity-scoped row isolation enforced at API layer.

Document Storage

Supabase Storage — SOC 2 compliant. Certificate PDFs and supporting documents stored with access-controlled signed URLs.

Entity Isolation

Every API call enforces entity_id scoping at the middleware layer. Users can only access their assigned entity. SUPER_ADMIN access is separately audited.

Encryption & Transport

Data Protection

Customer equity data is encrypted in transit and at rest using current industry standards.

LayerStandardStatus
Data in transit TLS 1.2+ enforced. HSTS with 2-year max-age and preload. HTTP connections redirected to HTTPS. ACTIVE
Data at rest — database AES-256 encryption via Neon PostgreSQL managed encryption. ACTIVE
Data at rest — documents AES-256 encryption via Supabase Storage managed encryption. ACTIVE
Authentication tokens JWT signed with HS256. 8-hour expiry. Server-side secret — no public key exposure. ACTIVE
Password storage bcryptjs with salt rounds=10. Passwords are never stored in plaintext or logged. ACTIVE
Access Control

Role-Based Permissions

All access is role-scoped and entity-scoped. No cross-entity data access is possible for non-admin roles.

RoleScopeCapabilities
SUPER_ADMIN Platform-wide Full access to all entities. All actions audited separately.
ENTITY_ADMIN Assigned entity only Full ledger management: issue, transfer, cancel, certificate lifecycle, user management.
MANAGER Assigned entity only Read and create transactions. Cannot delete records or manage users.
VIEWER Assigned entity only Read-only access to cap table, shareholders, and certificates.
Audit Trail

Immutable Audit Logging

Every ledger mutation is recorded with a full audit trail. Records cannot be modified or deleted by any user role.

What is logged

User ID, user email, role, entity ID, action type, resource type, resource ID, IP address, timestamp. All share issuances, transfers, cancellations, certificate actions, and user management events.

AI Governance Copilot

Every AI query is logged with user, entity, mode, message, response, tools called, token counts, and latency. The Copilot cannot execute ledger mutations — it is read-only by design.

Data Freshness

Cap table views show an as-of timestamp. Review attestations track when a human last verified the ledger. STALE data (no review in 90+ days) triggers a visible platform warning.

Document Provenance

Every share transfer, cancellation, and certificate action can attach supporting documents (stock power, letter of instruction, notary verification). Documents are linked to the ledger record permanently.

Compliance Roadmap

Certifications & Standards

Current status and roadmap for enterprise compliance certifications.

StandardStatusNotes
SOC 2 Type II IN PROGRESS Audit program initiated. Observation period underway. Report expected Q3 2026. Available to enterprise prospects under NDA upon completion.
GDPR-Ready Architecture AVAILABLE Entity-scoped data isolation, data export capability, and deletion workflows. Data Processing Agreement (DPA) available for enterprise customers upon request.
Delaware DGCL § 224 DESIGNED FOR Platform workflows are designed around Delaware electronic stock ledger requirements. Not a substitute for legal counsel review of corporate records.
CCPA AVAILABLE Data export and deletion capabilities available. Privacy policy covers California resident rights.
Penetration Testing PLANNED Annual third-party penetration test planned for Q2 2026. Results available to enterprise customers under NDA.
Enterprise customers: Security documentation, DPA, and SOC 2 bridge letter are available under NDA. Contact security@aegisiqstockledger.com to request.
Incident Response

Vulnerability Disclosure & Incident Response

We take security reports seriously and respond within 48 hours.

Report a Vulnerability

Email security@aegisiqstockledger.com with a description of the vulnerability, reproduction steps, and potential impact. We will acknowledge within 48 hours and provide updates throughout the resolution process.

Incident Notification

In the event of a security incident affecting customer data, affected customers will be notified within 72 hours of confirmed breach identification, consistent with applicable legal requirements.

Recovery Objectives

Recovery Point Objective (RPO): < 1 hour via Neon continuous backup. Recovery Time Objective (RTO): < 4 hours. Tested annually.

Data Ownership

Your Data Remains Yours

AegisIQ does not aggregate, resell, train AI models on, or analyze your equity records for any purpose other than operating the platform for your benefit.

Export Anytime

Export your full cap table, ledger history, and shareholder records at any time in standard formats. You are never locked in.

No Data Monetization

Your equity records are not used for benchmarking, sold to third parties, or used to train AI models outside your entity scope.

Deletion on Request

Enterprise customers may request full data deletion upon contract termination. Deletion confirmation provided within 30 days.