Trust

Security at Fiducia,
by the principles we sell.

Governance is our product. It is also how we run. We hold our own estate to the standard we ask of yours: least privilege, defense in depth, controls that are monitored continuously, and decisions that can be re-derived.

How we think about it

Least privilege

Access is granted only for a legitimate business need, and only at the level that need requires.

Defense in depth

Controls are layered, so no single failure exposes the estate.

Continuous monitoring

Controls are checked continuously, not audited once a year and forgotten.

Reproducibility

The same input produces the same result, so any decision can be re-derived for an examiner.

The controls

Practiced across the estate, not just the diagram.

Data protection

  • Data in transit is encrypted with TLS 1.3.
  • Data at rest is encrypted with AES-256.
  • Application secrets live in AWS Secrets Manager and SSM Parameter Store, never in source control.

Access control

  • Access follows least privilege and is granted by role.
  • Single sign-on and multi-factor authentication protect administrative systems.
  • Access is removed promptly when someone changes role or leaves.

Infrastructure

  • The platform runs on Amazon Web Services, with environments separated by stage.
  • Object storage is private and reachable only through the CDN using origin access control.
  • Infrastructure is defined as code, and changes are reviewed before they ship.
  • Plain HTTP is redirected to HTTPS across every property.

Product security

  • Changes go through peer review and an automated build and test pipeline.
  • Third-party dependencies are tracked and kept current.
  • We commission external, unauthenticated security assessments and remediate what they find.

Monitoring & compliance

  • Controls are monitored continuously with Vanta.
  • A SOC 2 programme is in place, with policies effective January 2026 and the Type II examination in progress. The current attestation status and report are available under NDA.
  • Access and change events are logged.

People & resilience

  • Everyone with access to sensitive data completes security and privacy training on hire and every year after.
  • Data is backed up, and infrastructure can be rebuilt from code.

Responsible disclosure

Found something? We want to hear from you.

Email security@fiduciaos.ai. Our contact and disclosure policy are published at /.well-known/security.txt. We will acknowledge your report and keep you updated as we work it.

Need our compliance documentation? Contact contact@fiduciaos.ai or book a session.

Bring your hardest control.

A 30 minute working session against a control, an agent, or a rule you already answer to.

Book a demo