Doc. AQ-SEC-01 · Security posture

Controls we operate, stated without adjectives.

A summary of how the platform is built and run, written for the person who has to sign a vendor assessment. Detailed control mappings and attestations are issued under NDA.

01

Tenancy and access model

Every record is scoped to a tenancy and enforced at the database layer through row-level policies, not only in application code. Access inside a tenancy is role-based: viewer, custodian, operator and administrator. Enterprise tenancies can enforce SSO with SCIM deprovisioning and custom role definitions.

02

Encryption

Data is encrypted in transit with TLS 1.2 or above and at rest by the managed storage layer. Certificates and evidence bundles are stored in object storage with per-object access control and time-limited signed URLs rather than public paths.

03

Immutable audit logging

Custody and sanitization events are append-only. A correction is recorded as a new event referencing the prior state; nothing is overwritten. Each certificate carries a SHA-256 digest of the underlying record so an auditor can verify the copy they were handed matches the copy we hold.

04

Sanitization assurance

Method selection follows the media controller rather than a fleet default, per NIST SP 800-88r1. Verification is mandatory: a job that cannot be verified is escalated to physical destruction rather than closed as successful. Failed verifications are surfaced in the customer dashboard, not suppressed.

05

Standards observed

  • NIST SP 800-88r1 — media sanitization (Clear, Purge, Destroy).
  • R2v3 — responsible recycling for processors and downstream vendors.
  • ISO/IEC 27001:2022 Annex A.8.10 — information deletion practices.
  • SOC 2 Type II criteria — security, availability and confidentiality.

06

Vulnerability reporting

Report suspected vulnerabilities to security@autonomiq.app. We acknowledge within one business day, provide a triage outcome within five, and will not pursue legal action against good-faith research that avoids privacy violations, service degradation and data destruction. Please do not test against a live customer tenancy.

07

Incident response

Incidents are triaged by severity with a named incident commander. Customers affected by a confirmed security incident involving their data are notified without undue delay and receive a written summary of scope, cause and remediation once the investigation closes.

08

Requesting evidence

Vendor assessment packs, attestation reports, penetration test summaries and the downstream vendor disclosure list are available under NDA. Request them through the contact page and name the assessment you are completing so we send the right bundle.

Statements on this page describe AUTONOMIQ's own operating practices as of the update date above. Independent attestations are provided as separate documents on request.