Skip to content
Assurance roadmap

Dated Assurance Roadmap

Aurora Command is pre-certification. This roadmap states plainly what is completed, what is in progress, and what is planned, each with a date and a source. It does not claim SOC 2, ISO 27001, FedRAMP, HIPAA, or PCI certification, an uptime percentage, an SLA, or a penetration-test result.

Completed

Completed

Substantiated directly by the repository: legal publications, infrastructure configuration, and CI-enforced security automation.

ImplementedIn place as of July 31, 2026

Per-Tenant Infrastructure Isolation

Each tenant is provisioned from a dedicated Terraform stack: its own VPC, subnets, security groups, database, and encrypted evidence storage.

Source: terraform/modules/tenant_stack/main.tf

ImplementedIn place as of July 31, 2026

Encryption in Transit and at Rest

TLS with HSTS is enforced across the public site and application. The production database has storage encryption enabled, and evidence storage uses a dedicated per-tenant key.

Source: deploy/nginx.ssl.conf.template; terraform/modules/tenant_stack/main.tf

ImplementedVerified against repo March 29, 2026

Automated Security Scanning in CI

Static analysis, secret scanning, dependency scanning, and infrastructure-as-code scanning run on every pull request, with nightly dynamic scanning against a target environment.

Source: docs/security/fleet/02-scanner-catalog.md

ImplementedCompleted January 3, 2026

Internal Full-Spectrum Security Review

An internal (non-third-party) attack-surface review and remediation tracker covering the frontend, backend, and infrastructure. Superseded day to day by the current architecture and security documentation.

Source: docs/security/security-review-2026-01-03.md

AvailableEffective March 15, 2026

Data Processing Addendum Published

Covers processor obligations, subprocessor notice mechanics, security measures, and deletion/return of Customer Personal Data.

Source: /data-processing-addendum

AvailableEffective March 15, 2026

Vulnerability Disclosure Policy Published

A controlled public channel for good-faith security researchers to report findings.

Source: /vulnerability-disclosure

AvailablePublished July 31, 2026

Subprocessor Register and Data-Handling Matrix Published

This assurance program's first public artifacts: the named subprocessor list, change-notification mechanics, and the data-handling matrix.

Source: /subprocessors, /data-handling

In progress

In Progress

Work that is underway or has a defined scope, but is not yet complete.

ImplementedOngoing, reviewed on a recurring cycle

Security and Architecture Documentation Maintenance

Aurora's internal security and architecture documentation set carries a defined review cadence and is kept current against the live repository rather than published once and left static.

Source: docs/security/**, docs/architecture/security.md

PlannedScoping drafted; engagement not yet scheduled

Voice Operations Threat Model and Pen-Test Scoping

A formal threat model and a penetration-test scope brief for the Voice Operations module, ahead of scheduling an external or internal engagement.

Source: internal workorder tracking

Planned

Planned

Not started. Listed here instead of left silent, so buyers see the honest gap rather than an assumption.

PlannedNo date set

Independent Third-Party Penetration Test

A penetration test of the Aurora Command platform performed by an independent third party. No vendor or date has been selected yet.

Source: owner action

PlannedNo date set

Fill Remaining Subprocessor Detail Gaps

Several subprocessor rows list region as not yet published because the repository does not establish it today. Closing those gaps is an owner action, not a guess.

Source: /subprocessors

PlannedNo date set

Independent Certification or Attestation Review

Aurora is pre-certification. No SOC 2, ISO 27001, FedRAMP, HIPAA, or PCI certification is claimed today, and none has a scheduled target date.

Source: owner action