> For the complete documentation index, see [llms.txt](https://aude-1.gitbook.io/aude/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aude-1.gitbook.io/aude/policies/security-policy.md).

# Security Policy

At Aude, the security of your data is our highest priority. We incorporate industry-leading security practices across our platform, infrastructure, and operations. This document details our security measures, data handling processes, and compliance commitments.

***

### 🔐 Overview <a href="#overview" id="overview"></a>

Security, reliability, privacy, and compliance underpin everything we do at Aude. Our approach combines best practices informed by industry standards and deep expertise from leading global software companies.

***

### 📑 Organizational Security Controls <a href="#organizational-security-controls" id="organizational-security-controls"></a>

#### Employee Access and Training <a href="#employee-access-and-training" id="employee-access-and-training"></a>

* Access to customer data is strictly limited to authorized personnel and is on a **need-to-know** basis.
* All employees complete regular security awareness training, emphasizing confidentiality and responsible data handling.
* Criminal background checks are conducted for employees with access to customer data.

#### Confidentiality <a href="#confidentiality" id="confidentiality"></a>

* Employees are required to sign confidentiality agreements to ensure proprietary and customer information remains protected.

***

### ☁️ Cloud Infrastructure <a href="#cloud-infrastructure" id="cloud-infrastructure"></a>

#### Hosting Provider <a href="#hosting-provider" id="hosting-provider"></a>

* Aude services are hosted using industry-standard cloud infrastructure providers (e.g., AWS, GCP).
* Data centers are regularly audited and meet compliance standards including **SOC 2 Type II**, **ISO 27001**, and GDPR readiness.
* Infrastructure providers offer physical and logical security measures, redundancy, and robust disaster recovery capabilities.

#### Data Residency <a href="#data-residency" id="data-residency"></a>

* Aude currently stores customer data in **Australia (AWS ap-southeast-2)** with regular backups for disaster recovery purposes.

#### Encryption <a href="#encryption" id="encryption"></a>

* All data is encrypted using **AES-256** encryption at rest.
* Data in transit is secured with **TLS 1.2 or higher**.

***

### 🛠️ Technical Security Measures <a href="#technical-security-measures" id="technical-security-measures"></a>

#### Secure Software Development <a href="#secure-software-development" id="secure-software-development"></a>

* Secure coding practices and regular static code analysis are implemented throughout our software development lifecycle.
* Dependencies are continuously monitored for known vulnerabilities.

#### Network and Application Security <a href="#network-and-application-security" id="network-and-application-security"></a>

* Infrastructure is isolated behind multiple layers of firewalls.
* Application servers and databases are logically separated to further mitigate risk.
* User access to the platform requires authenticated sessions using HTTPS.

#### Authentication and Access Control <a href="#authentication-and-access-control" id="authentication-and-access-control"></a>

* Aude supports Single Sign-On (SSO) via **OAuth** protocols.
* Multi-factor Authentication (MFA) is enforced for all administrative access.
* Passwords and sensitive credentials are never stored in plaintext.

***

### 📂 Data Collection and Handling <a href="#data-collection-and-handling" id="data-collection-and-handling"></a>

#### Data We Collect <a href="#data-we-collect" id="data-we-collect"></a>

* Aude collects and processes only the data necessary to provide our services, including:
  * Source code and repository metadata
  * Issue tracking data (e.g., Jira ticket context)
  * Basic user account information for authentication (name, email)

#### Data We Do Not Collect <a href="#data-we-do-not-collect" id="data-we-do-not-collect"></a>

* Sensitive personal data or credentials beyond what is explicitly required for authorized integrations.

***

### 🔍 Logging, Monitoring, and Audit <a href="#logging-monitoring-and-audit" id="logging-monitoring-and-audit"></a>

#### System Monitoring <a href="#system-monitoring" id="system-monitoring"></a>

* Real-time monitoring and logging to detect unauthorized activities or anomalies.
* Security incidents trigger alerts and immediate response procedures.

#### Audit Logging (Planned) <a href="#audit-logging-planned" id="audit-logging-planned"></a>

* Detailed audit logs are maintained, tracking access and system activities.

#### Security Incident and Event Management (SIEM) <a href="#security-incident-and-event-management-siem" id="security-incident-and-event-management-siem"></a>

* Integration capabilities with common SIEM platforms for enterprise customers.

***

### 🚨 Incident Management <a href="#incident-management" id="incident-management"></a>

#### Incident Management <a href="#incident-management" id="incident-management"></a>

* We have a clearly defined incident response plan to rapidly detect, investigate, mitigate, and communicate security incidents.
* Customers are notified within **24 hours** of confirmed security incidents impacting their data.

#### Responsible Disclosure <a href="#responsible-disclosure" id="responsible-disclosure"></a>

* Aude welcomes security reports and vulnerabilities via our responsible disclosure program. Report issues securely at: [**Daniel@aude.app**](mailto:security@aude.ai)

***

### 📜 Compliance and Certifications <a href="#compliance-and-certifications" id="compliance-and-certifications"></a>

* **SOC 2 Type I Certification:** In progress, expected completion end-2025.
* **GDPR Compliance:** Aude does not store personal data of users, and is not subject to GDPR.
* **ISO 27001 Certification:** Planned for early 2026.

***

### 🔄 Subprocessors and Third-party Management <a href="#subprocessors-and-third-party-management" id="subprocessors-and-third-party-management"></a>

* Aude maintains an updated list of subprocessors (such as cloud hosting providers, logging platforms).
* All subprocessors undergo thorough security assessments before onboarding.
* List available on request: [**Daniel@aude.app**](mailto:security@aude.ai)

***

### ⚖️ AI Processing and Data Governance <a href="#ai-processing-and-data-governance" id="ai-processing-and-data-governance"></a>

* **No data retention or model training:** Customer data is strictly used for service delivery and never utilized to train AI models.
* Requests to AI providers are transmitted individually over encrypted channels (TLS).
* Data isolation ensures customer-specific information remains confined to customer-specific instances.

***

### ❌ Exclusions and Limitations <a href="#exclusions-and-limitations" id="exclusions-and-limitations"></a>

This policy does not cover:

* Data or interactions with third-party services that are not explicitly integrated within Aude.
* Data stored outside of Aude’s platform or control (e.g., customer VPNs or third-party networks not managed by Aude).

***

### 📮 Contact and Reporting Security Issues <a href="#contact-and-reporting-security-issues" id="contact-and-reporting-security-issues"></a>

For security inquiries, reporting vulnerabilities, or additional documentation, please contact:

* [**Daniel@aude.app**](mailto:security@aude.ai)

Aude is committed to transparency, security excellence, and protecting your valuable data assets. Thank you for placing your trust in us.

***

### 🔗 Policy Updates <a href="#policy-updates" id="policy-updates"></a>

We regularly review and update this policy. Changes will be communicated via the Aude support website.<br>
