Public trust record
Aranis Beta's security posture, open and verifiable.
This is the living record of our controls, certifications, and compliance commitments — the same risk causal chain we apply to our customers, applied to ourselves.
Certifications and attestations
What has already been audited by third parties
Every certification below is verifiable in the issuer's public registry. Expired certifications are not shown.
- CAIQ v4.0.3ACTIVE

CSA STAR Level 1
Cloud Security Alliance
Level: Level 1 - Self-Assessment
- Issued on
- Jul 07, 2026
- Last reviewed
- Jul 06, 2026
Security posture
How we protect the data that flows through Aranis Beta
Our Security Posture Document describes, in detail, the technical and organizational controls that underpin Aranis Beta — from access governance to incident response.
Controls
Our controls, organized by domain
These are the organization's own controls — informed by the CSA CCM, but written and maintained as part of our own risk methodology.
Vendor chain
Subprocessors
Third parties that process data on the organization's behalf, so you know exactly where and with whom your data travels.
| Vendor | Purpose | Data types | Data location | DPA |
|---|---|---|---|---|
| Supabaseinfrastructure | Database, authentication, and storage | — | us-west-2 (AWS) | View |
| Vercelinfrastructure | Application hosting and deployment | — | United States (primary processing; infrastructure globally replicated) | View |
| GitHubinfrastructure | Source code hosting and CI/CD | — | — | View |
| Anthropic (Claude)ai | Language model for the orchestrator agent and report generation | — | — | View |
| Cloudflare (Turnstile)security | Bot protection on forms | — | — | View |
| Better Stackmonitoring | Uptime monitoring and status page | — | — | View |
| Resendinfrastructure | Transactional email delivery | — | United States | View |
| Stripepayments | Payment processing and billing | — | — | View |
Compliance roadmap
Where we're headed
We'd rather show what's still under construction than hide it — maturity is a trajectory, not a single badge.
Independent external audit
PlannedAudit and assurance assessment conducted by independent third parties, complementing the current CSA STAR self-assessment.
Customer-managed encryption keys (BYOK)
PlannedCapability for enterprise customers to manage their own data encryption keys.
Third-party penetration testing
PlannedPeriodic penetration tests conducted by a specialized independent firm.
Endpoint Data Loss Prevention (DLP)
PlannedDLP technologies configured on managed endpoints, based on risk assessment.
Frequently asked questions
What buyers usually ask
access
data
security
compliance
security
ai
security
data