Security & Trust

Built for the data regulators care about.

IronArchitects handles the most sensitive material an organization has: its architecture, its controls, and the evidence behind them. Tenant isolation, audit integrity, least-privilege access, and AI guardrails are designed in, not bolted on.

Tenant isolation & data protection

Isolation enforced by the database, not just the app.

Row-level security with FORCE RLS

Every query is scoped to the tenant at the database layer with PostgreSQL row-level security in FORCE mode, backed by a per-request org context and a least-privilege application role. Even an application bug cannot leak cross-tenant data.

Encryption in transit & secret hygiene

All traffic is encrypted with TLS 1.2+. Platform secrets, including API keys, webhook secrets, and SMTP credentials, are stored encrypted and can be rotated without a redeploy.

Customer-managed keys roadmap

Customer-managed keys (CMEK/BYOK) and field-level encryption for PHI, cardholder data, and PII, an Enterprise option for the most regulated tenants.

Data residency & deployment roadmap

Region pinning and single-tenant or VPC deployment options for Enterprise organizations with strict residency and isolation requirements.

Identity & access

Your identity provider, your roles, your rules.

Enterprise single sign-on

Authentication runs on Keycloak with OAuth 2.0 / OIDC. Federate Microsoft Entra ID, Okta, or any OIDC-compliant identity provider; separate realms isolate platform administration from tenant access.

SCIM 2.0 provisioning

Automated provisioning and deprovisioning from your IdP over SCIM 2.0, Users and Groups, with group-to-role mapping. Offboard in the IdP and access is revoked here.

Enforced MFA & session controls

Organization-enforced multi-factor authentication and configurable session timeouts, so access policy is set once, at the org level, and applies to everyone.

Fine-grained RBAC & segregation of duties

16+ granular permissions compose custom roles for Compliance Officers, Privacy Officers, and Enterprise Architects. Segregation of duties is enforced at sign-off: the risk acceptor must differ from the approver, and self-approval is blocked.

Audit & evidence integrity

History you can prove, not just print.

Every consequential action becomes part of a tamper-evident record, from an architect's approval to an AI agent's verdict, so the evidence you hand an auditor is bound to what actually happened.

  • Hash-chained, append-only audit trail: approvals, overrides, risk acceptances, AI generation runs, and agent verdicts are all recorded tamper-evidently.
  • Audit chain verification and search built into the app, plus streaming SIEM export to Splunk, Datadog, or syslog with configurable retention policies.
  • Approved design versions are immutable, and a compliance evidence ledger ties each control decision to its record.
  • Legal holds freeze designs and evidence against deletion until the hold lifts.
# append-only audit chain 0x8f31 approval design v12 sealed prev 0x8e0c 0x8e0c risk.accept AU-9 · second principal prev 0x8cef 0x8cef agent.verdict security review · approve prev 0x8b12 0x8b12 generation.run 14 components · gemini prev 0x8a07 verify-chain OK 4,182 events · no breaks detected
Privacy & incident readiness

Ready for the request, and for the bad day.

Data-subject rights tooling

GDPR and CCPA workflows built in: portability export and erasure requests are handled with tooling that respects active legal holds, so privacy compliance never destroys litigation evidence.

Incident & breach response

Record a security or privacy incident and track its statutory notification deadlines automatically, HIPAA's 60 days and GDPR's 72 hours, with automated reminders on an append-only timeline that can be added to but never rewritten.

PII redaction

Personally identifiable information is redacted in platform logs and in AI responses, so sensitive values do not leak into operational tooling or model output.

AI safety

AI you can put in front of an auditor.

The AI engine is governed like any other principal in the system: constrained, monitored, and never the final authority. Guardrails are enforced in the platform, not left to the model's judgment.

  • Customer Content is never used to train models. Generation runs on Google Vertex AI under terms that prohibit it.
  • Prompt-injection detection on the architecture chat, with abuse alerts raised to org admins.
  • Every agent tool call, from CVE lookups to pricing queries, is validated against an outbound allowlist with DNS-rebinding protection.
  • Human approval is required before any design ships, and low-confidence AI decisions are flagged for review.
  • Discovery agents are read-only and metadata-only: schema and resource shapes are recorded, data values are unrepresentable, and every run requires an authorization attestation logged to an append-only trail.
# agent guardrails · outbound tool calls allow services.nvd.nist.gov CVE lookup · on allowlist allow prices.azure.com retail pricing · on allowlist block 169.254.169.254 not on allowlist · dropped pass dns-rebinding check IP re-verified at connect # architecture chat alert prompt-injection pattern org admins notified hold design awaiting approval human sign-off required
Compliance posture

Mapped to the frameworks your buyers audit.

IronArchitects is built to support the evidence collection and control mappings behind the frameworks regulated organizations are held to, the same frameworks it generates designs against.

  • Audit-integrity and evidence automation aligned to SOC 2 and ISO 27001.
  • Control packs for HIPAA/HITRUST, PCI-DSS v4, FedRAMP/NIST 800-53, NIST 800-171/CMMC, and more.
  • GDPR/CCPA data-subject rights: export, portability, and erasure.
  • BAA/DPA support and a subprocessor registry for procurement review.

Certifications such as SOC 2 Type II and ISO 27001 are pursued as the platform matures. Our security documentation and subprocessor list are available on request, and we're happy to share our current attestation status under NDA. Contact our security team.

SOC 2Trust services criteriaIn progress
ISO 27001ISMS controlsIn progress
HIPAASecurity & Privacy RuleSupported
GDPRData-subject rightsSupported
FedRAMPNIST 800-53 baselineRoadmap
Engineering practices

Security is part of how we build.

Hardened by architecture

A microservice topology behind an API gateway that owns authentication, routing, rate limiting, and org-context injection; internal services never trust unauthenticated traffic.

Continuous security review

Dependency scanning and security review run in CI. The same compliance scrutiny we apply to customer designs, we apply to our own platform.

Full-stack observability

Distributed tracing (OpenTelemetry) and RED metrics (Prometheus + Grafana dashboards) across every service, so issues are seen, diagnosed, and resolved fast.

Quotas & tenant fairness

Platform-configurable per-organization resource quotas and concurrency caps, connection pooling, and configurable upload limits keep one tenant from impacting another.

Request Our Security Documentation

Bring your security team. We like the hard questions.

Start free and see the isolation, audit chain, and AI guardrails for yourself, or request our security documentation and subprocessor list before you commit.