Security commitments

Security

How we protect your data, your documents, and your clients' confidentiality.

EU-First Infrastructure

Storage and database in EU regions; AI processing under EU SCCs, EU residency in progress.

AES-256 Encryption

All files encrypted at rest. All connections via TLS 1.2 minimum.

No AI Training

Your data is never used to train or fine-tune any AI model.

01

Infrastructure

Aturno's storage and database run in EU regions. Where a provider processes data outside the EEA, the transfer is covered by the EU Standard Contractual Clauses and an executed data processing agreement:

  • Cloudflare R2: encrypted file storage, EU region.
  • Convex: serverless database and backend with encrypted connections, EU region.
  • OpenAI: AI model processing under EU SCCs and a signed DPA; no training on your data. Until our zero-data-retention request is approved, OpenAI retains API inputs and outputs for up to 30 days solely for abuse monitoring, then deletes them. EU data residency and zero data retention requested.
  • Vercel: frontend hosting and global edge delivery (US entity, EU SCCs).
  • WorkOS: authentication and identity management (US entity, EU SCCs).
02

Encryption

Data is protected both at rest and in transit:

  • Encryption at rest: all files stored on Cloudflare R2 are encrypted using AES-256.
  • Encryption in transit: all connections use TLS 1.2 as a minimum. TLS 1.3 is used where supported.
  • Database connections: all connections use encrypted channels with certificate validation.
  • Key management: encryption keys are managed at the infrastructure level and are never exposed to application code.
03

Access Controls

We apply strict access controls across all systems:

  • Role-based access control (RBAC): access to production systems is limited to authorised personnel based on the principle of least privilege.
  • Audit logging: all access to production data and infrastructure is logged.
  • No shared credentials: each service and team member uses separate, individually scoped credentials.
  • Regular access reviews: access rights are reviewed periodically and revoked on personnel change.
04

Authentication

User authentication is managed by a specialist identity provider:

  • We do not store passwords. Authentication credentials are managed entirely by our identity provider.
  • Multi-factor authentication (MFA) is available and recommended for all users.
  • Session tokens are short-lived and cryptographically signed.
  • All authentication flows are protected against common attacks including brute force, credential stuffing, and session hijacking.
05

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a vulnerability in Aturno, please report it responsibly:

  • Email us at security@aturno.ai with a clear description of the issue.
  • Include steps to reproduce, potential impact, and any relevant technical details.
  • We will acknowledge your report within 72 hours and keep you updated on our response.
  • Please do not publicly disclose the vulnerability until we have had reasonable time to address it.

Report a vulnerability

security@aturno.ai

Start free today.

No credit card required to begin.