Security

SecuritybuiltforenterpriseAIteams

ARIA combines dedicated infrastructure, regional data residency, end-to-end encryption, and granular access controls so you can run adversarial AI evaluations without exposing sensitive model behaviour or conversation data.

SOC 2 Type II

Pursuing

GDPR

Pursuing

ISO 27001

Pursuing

8 Global Regions

Data residency

FCA Consumer Duty

Controls built in

Infrastructure

Isolatedbydesign,hardenedateverylayer

ARIA is deployed on AWS ECS Fargate with a multi-tenant architecture where each customer workspace runs in complete infrastructure isolation. No shared queues, no shared storage, no shared network paths.

Dedicated tenant infrastructure

Every ARIA workspace runs in its own isolated environment — separate ECS Fargate tasks, separate VPC, separate storage. Your evaluation data and transcripts never share compute or network paths with another customer.

Regional deployment & data residency

Choose from 8 global AWS regions at signup. Your workspace, transcripts, and judge outputs are created and stored in your selected region and never moved. Supports UK, EU, US, and APAC data residency requirements.

Encryption everywhere

All data in transit is protected by TLS 1.2+. Data at rest — transcripts, evaluation results, scenario YAML, database records — is encrypted with AES-256. Secrets are stored in AWS Secrets Manager, never in environment variables or code.

Hardened container runtime

ARIA runs on AWS ECS Fargate — a serverless compute layer with no persistent host access. Containers are rebuilt from scratch on every deployment. Docker images are scanned on push via ECR. No SSH access to production compute.

Data protection

Yourevaluationdatastaysyours

Transcripts contain full conversational content. We treat them as your most sensitive data — stored in your region, encrypted at rest, and never used for ARIA's own model training or analytics.

TLS 1.2+ in transit

All API calls, SSE streams, and UI traffic are encrypted in transit. CloudFront enforces HTTPS-only with HSTS headers.

AES-256 at rest

Database records, transcript files, and report exports are encrypted at rest. Customer-managed keys available on Enterprise plans.

Regional storage

S3 buckets, RDS, and ECS task storage are created in your chosen region. No cross-region replication is enabled by default.

Transcript isolation

Each transcript is written to a path namespaced by tenant and run ID. Files are accessible only to your workspace IAM role.

Secrets never in logs

Production logging strips passwords, tokens, API keys, and private keys. Provider credentials are injected via Secrets Manager at task start.

No training use

ARIA does not use your transcripts, scenarios, or evaluation results to train or fine-tune any model.

Access & identity

Least-privilegeaccess,endtoend

ARIA enforces the principle of least privilege at every layer — from individual user permissions within a workspace to the IAM roles that govern what each ECS task can touch in AWS.

Role-based access control

Owner, Admin, and Member roles with granular permissions. Workspace owners control who can create runs, approve reviews, export reports, or modify settings.

Single sign-on (SSO)

Federate access through Google or GitHub OIDC. Enterprise plans support Cognito-brokered SSO for custom identity providers.

Audit log

Every mutation — scenario changes, run launches, review approvals, team changes, setting updates — is recorded with timestamp, actor, IP address, and user-agent. Immutable and exportable.

Session security

Short-lived JWT access tokens (15 minutes) with rotating refresh tokens. Sessions are invalidated on logout. Concurrent session limit enforced. 30-minute idle timeout.

Secrets management

Provider credentials (Bedrock, Connect, Lex, Azure) are stored in AWS Secrets Manager and injected at container start. They are never written to disk, logs, or database.

Network isolation

Each workspace VPC has no inbound internet access except through an Application Load Balancer protected by a CloudFront origin-secret header. ECS tasks have no public IPs.

Compliance

Controlsalignedtotheframeworksthatmatter

ARIA is used by regulated-industry teams evaluating AI agents that handle financial advice, health information, and customer service. The compliance controls and evaluation dimensions are built with those requirements in mind.

FCA Consumer Duty

Built in

A dedicated Vulnerability Detection dimension identifies distress signals — financial difficulty, bereavement, mental health, coercion — and scores whether the agent handled them correctly. Escalation Appropriateness dimensions validate complaint and transfer flows against FCA policy.

GDPR

Pursuing

Evaluation data stays in your chosen region. User accounts support suspension (Article 18). Transcripts are pseudonymised when test customer personas are used. Data processing agreements available for enterprise plans.

SOC 2 Type II

In progress

Building toward SOC 2 Type II across Security, Availability, and Confidentiality criteria. CloudTrail is enabled across all regions with 1-year retention, 90-day CloudWatch retention, and CIS alarm controls.

HIPAA

Aligned

Workspaces can be deployed in HIPAA-eligible AWS regions. Encryption at rest and in transit, audit logging, and access controls align with HIPAA Technical Safeguard requirements. BAA available for enterprise plans.

PCI DSS

Partial

ARIA does not store, transmit, or process payment card data. Payment-related dialogue is handled as text-only test content; no live payment systems are connected.

ISO 27001

Pursuing

Information security practices align with ISO 27001 Annex A controls covering access control, cryptography, physical security, operations security, and incident management.

Operational security

Continuousmonitoring,notjustcontrolsonpaper

ARIA deploys CloudTrail across all regions with 1-year S3 retention and 90-day CloudWatch log groups. CIS benchmark alarms alert on credential misuse, network policy changes, and unauthorised API calls. WAF rate limits protect every CloudFront distribution.

  • All production deployments are separated from staging by network boundary and IAM policy.
  • CloudTrail multi-region logging with CloudWatch alerting on CIS benchmark triggers.
  • WAF rate limiting (2,000 req/5min) on all CloudFront distributions.
  • ECR image vulnerability scanning on every push.
  • Secrets rotation supported via Terraform taint + ECS force-deployment pattern.
  • No secrets in Terraform state for runtime credentials — bootstrap-only pattern.
  • Vulnerability disclosure

    We welcome responsible disclosure of security vulnerabilities. If you discover an issue, please report it privately before public disclosure. We aim to acknowledge reports within 2 business days and resolve critical issues within 90 days.

    Security documentation

    Enterprise and Enterprise Pro plans include access to ARIA's full security documentation package — architecture diagrams, data flow maps, control evidence, and vendor questionnaire (VSQ) responses. Available under NDA on request.

    Ready to evaluate securely

    Security that scales with your AI ambitions

    Start with the Free plan and evaluate up to 5 runs — no infrastructure to manage. Scale into dedicated tenancy when your compliance requirements demand it.