Security

What protects your data, and what we can't claim yet

Tax data is among the most sensitive material a finance team holds. This page is written to be read by whoever has to sign off on us — including the half that is inconvenient for us.

In place today

  • Tenant isolation enforced in the database

    Every transaction row carries its tenant. Access rules are applied by the database itself, not by application code that could be bypassed, so one customer's query cannot reach another's data even if the app is wrong.

  • Encryption in transit and at rest

    TLS on every connection; managed encryption at rest on the database and object storage. Nothing tax-related is stored on developer machines.

  • Immutable audit trail

    Determinations, overrides, exports and administrative actions are append-only records with actor and timestamp. They are part of the product, not an internal log we could quietly rewrite.

  • Least-privilege access

    Only the people working on your engagement can reach your data, and only through the platform. There is no shared login and no bulk download of customer data as a working practice.

  • Deletion on request

    You can ask for a full export and deletion of your tenant at any time, including during a pilot. Backups age out on the platform's own retention window and we will state that window in writing before a pilot begins.

  • Payments handled by the processor

    Card and bank details are captured and stored by Razorpay, our PCI-DSS compliant payment processor. Aurevat never sees or stores card numbers.

Not in place yet

  • SOC 2 Type II / ISO 27001

    Not held. We will not display a badge or imply readiness we have not been audited for. If your procurement process requires certification today, Aurevat is too early for you and we would rather say so now.

  • Penetration test report

    No independent test has been commissioned yet. It is planned before general availability, and the summary will be shareable under NDA when it exists.

  • Contractual uptime SLA on lower plans

    A response SLA is offered on Enterprise. An availability SLA will be published when we have the operating history to back a number.

  • Data residency choice

    Not yet configurable. We will tell you exactly where your data sits before a pilot starts, in writing.

Reporting a vulnerability

If you find a security issue, email info@aurevat.com with the detail needed to reproduce it. You will get a human acknowledgement within one business day. We will not pursue anyone acting in good faith who reports privately and avoids accessing other people's data.