Dedicated tenant infrastructure
Every ARIA workspace runs in its own isolated environment — separate ECS Fargate tasks, separate VPC, separate storage. Your evaluation data and transcripts never share compute or network paths with another customer.
Security
ARIA combines dedicated infrastructure, regional data residency, end-to-end encryption, and granular access controls so you can run adversarial AI evaluations without exposing sensitive model behaviour or conversation data.
SOC 2 Type II
Pursuing
GDPR
Pursuing
ISO 27001
Pursuing
8 Global Regions
Data residency
FCA Consumer Duty
Controls built in
Infrastructure
ARIA is deployed on AWS ECS Fargate with a multi-tenant architecture where each customer workspace runs in complete infrastructure isolation. No shared queues, no shared storage, no shared network paths.
Every ARIA workspace runs in its own isolated environment — separate ECS Fargate tasks, separate VPC, separate storage. Your evaluation data and transcripts never share compute or network paths with another customer.
Choose from 8 global AWS regions at signup. Your workspace, transcripts, and judge outputs are created and stored in your selected region and never moved. Supports UK, EU, US, and APAC data residency requirements.
All data in transit is protected by TLS 1.2+. Data at rest — transcripts, evaluation results, scenario YAML, database records — is encrypted with AES-256. Secrets are stored in AWS Secrets Manager, never in environment variables or code.
ARIA runs on AWS ECS Fargate — a serverless compute layer with no persistent host access. Containers are rebuilt from scratch on every deployment. Docker images are scanned on push via ECR. No SSH access to production compute.
Data protection
Transcripts contain full conversational content. We treat them as your most sensitive data — stored in your region, encrypted at rest, and never used for ARIA's own model training or analytics.
All API calls, SSE streams, and UI traffic are encrypted in transit. CloudFront enforces HTTPS-only with HSTS headers.
Database records, transcript files, and report exports are encrypted at rest. Customer-managed keys available on Enterprise plans.
S3 buckets, RDS, and ECS task storage are created in your chosen region. No cross-region replication is enabled by default.
Each transcript is written to a path namespaced by tenant and run ID. Files are accessible only to your workspace IAM role.
Production logging strips passwords, tokens, API keys, and private keys. Provider credentials are injected via Secrets Manager at task start.
ARIA does not use your transcripts, scenarios, or evaluation results to train or fine-tune any model.
Access & identity
ARIA enforces the principle of least privilege at every layer — from individual user permissions within a workspace to the IAM roles that govern what each ECS task can touch in AWS.
Owner, Admin, and Member roles with granular permissions. Workspace owners control who can create runs, approve reviews, export reports, or modify settings.
Federate access through Google or GitHub OIDC. Enterprise plans support Cognito-brokered SSO for custom identity providers.
Every mutation — scenario changes, run launches, review approvals, team changes, setting updates — is recorded with timestamp, actor, IP address, and user-agent. Immutable and exportable.
Short-lived JWT access tokens (15 minutes) with rotating refresh tokens. Sessions are invalidated on logout. Concurrent session limit enforced. 30-minute idle timeout.
Provider credentials (Bedrock, Connect, Lex, Azure) are stored in AWS Secrets Manager and injected at container start. They are never written to disk, logs, or database.
Each workspace VPC has no inbound internet access except through an Application Load Balancer protected by a CloudFront origin-secret header. ECS tasks have no public IPs.
Compliance
ARIA is used by regulated-industry teams evaluating AI agents that handle financial advice, health information, and customer service. The compliance controls and evaluation dimensions are built with those requirements in mind.
A dedicated Vulnerability Detection dimension identifies distress signals — financial difficulty, bereavement, mental health, coercion — and scores whether the agent handled them correctly. Escalation Appropriateness dimensions validate complaint and transfer flows against FCA policy.
Evaluation data stays in your chosen region. User accounts support suspension (Article 18). Transcripts are pseudonymised when test customer personas are used. Data processing agreements available for enterprise plans.
Building toward SOC 2 Type II across Security, Availability, and Confidentiality criteria. CloudTrail is enabled across all regions with 1-year retention, 90-day CloudWatch retention, and CIS alarm controls.
Workspaces can be deployed in HIPAA-eligible AWS regions. Encryption at rest and in transit, audit logging, and access controls align with HIPAA Technical Safeguard requirements. BAA available for enterprise plans.
ARIA does not store, transmit, or process payment card data. Payment-related dialogue is handled as text-only test content; no live payment systems are connected.
Information security practices align with ISO 27001 Annex A controls covering access control, cryptography, physical security, operations security, and incident management.
Operational security
ARIA deploys CloudTrail across all regions with 1-year S3 retention and 90-day CloudWatch log groups. CIS benchmark alarms alert on credential misuse, network policy changes, and unauthorised API calls. WAF rate limits protect every CloudFront distribution.
We welcome responsible disclosure of security vulnerabilities. If you discover an issue, please report it privately before public disclosure. We aim to acknowledge reports within 2 business days and resolve critical issues within 90 days.
Enterprise and Enterprise Pro plans include access to ARIA's full security documentation package — architecture diagrams, data flow maps, control evidence, and vendor questionnaire (VSQ) responses. Available under NDA on request.
Ready to evaluate securely
Start with the Free plan and evaluate up to 5 runs — no infrastructure to manage. Scale into dedicated tenancy when your compliance requirements demand it.