Security commitments
Security
How we protect your data, your documents, and your clients' confidentiality.
EU-First Infrastructure
Storage and database in EU regions; AI processing under EU SCCs, EU residency in progress.
AES-256 Encryption
All files encrypted at rest. All connections via TLS 1.2 minimum.
No AI Training
Your data is never used to train or fine-tune any AI model.
Contents
Infrastructure
Aturno's storage and database run in EU regions. Where a provider processes data outside the EEA, the transfer is covered by the EU Standard Contractual Clauses and an executed data processing agreement:
- Cloudflare R2: encrypted file storage, EU region.
- Convex: serverless database and backend with encrypted connections, EU region.
- OpenAI: AI model processing under EU SCCs and a signed DPA; no training on your data. Until our zero-data-retention request is approved, OpenAI retains API inputs and outputs for up to 30 days solely for abuse monitoring, then deletes them. EU data residency and zero data retention requested.
- Vercel: frontend hosting and global edge delivery (US entity, EU SCCs).
- WorkOS: authentication and identity management (US entity, EU SCCs).
Encryption
Data is protected both at rest and in transit:
- Encryption at rest: all files stored on Cloudflare R2 are encrypted using AES-256.
- Encryption in transit: all connections use TLS 1.2 as a minimum. TLS 1.3 is used where supported.
- Database connections: all connections use encrypted channels with certificate validation.
- Key management: encryption keys are managed at the infrastructure level and are never exposed to application code.
Access Controls
We apply strict access controls across all systems:
- Role-based access control (RBAC): access to production systems is limited to authorised personnel based on the principle of least privilege.
- Audit logging: all access to production data and infrastructure is logged.
- No shared credentials: each service and team member uses separate, individually scoped credentials.
- Regular access reviews: access rights are reviewed periodically and revoked on personnel change.
Authentication
User authentication is managed by a specialist identity provider:
- We do not store passwords. Authentication credentials are managed entirely by our identity provider.
- Multi-factor authentication (MFA) is available and recommended for all users.
- Session tokens are short-lived and cryptographically signed.
- All authentication flows are protected against common attacks including brute force, credential stuffing, and session hijacking.
Responsible Disclosure
We take security vulnerabilities seriously. If you discover a vulnerability in Aturno, please report it responsibly:
- Email us at security@aturno.ai with a clear description of the issue.
- Include steps to reproduce, potential impact, and any relevant technical details.
- We will acknowledge your report within 72 hours and keep you updated on our response.
- Please do not publicly disclose the vulnerability until we have had reasonable time to address it.
Report a vulnerability
security@aturno.ai