A current view of the Azure SaaS platform, application services, PostgreSQL and Blob persistence, identity/RBAC, tenant isolation, hardened integration boundaries, monitoring, secure delivery, release integrity and tested recovery controls.
The complete path from product selection and organisation ownership through MFA, paid entitlements, seat controls, invitations, roles, initial project/programme or Blueprint scope, telemetry setup, the first control review and onboarding acceptance.
How to use Projects, Programmes, Blueprint and the Admin Centre as a control system: observe evidence, assess system impact, preview a response, commit an authorised intervention and verify what happened next.
Connector principles and operating patterns for Jira, Azure DevOps, Dynamics 365, Power BI, SAP, Azure Resource Graph and CMDB/asset evidence, including provenance and fresh/ageing/stale/silent telemetry assurance.
Partner-facing guidance for qualifying prospects, running discovery and demos, handling common objections, maintaining claims discipline, working with regulated buyers and turning both wins and losses into useful market feedback.
The proposed assurance scope, current technical evidence, organisational controls still to formalise, evidence-register model, shared-responsibility boundary and external audit path for ISO/IEC 27001:2022 certification preparation and a future SOC 2 Type II examination.
Implemented identity, tenant, integration, recovery, CI/CD, data-protection and request-hardening controls, plus the boundary between AIDE's standard SaaS baseline and planned defence-in-depth work.
Procurement-friendly entry points, indicative subscription model, Australian-hosted cloud posture and information useful to Commonwealth/state buyers and security/procurement reviewers.
Support coverage, priority/response targets, customer-support entry points and links to public documentation for self-service evaluation and onboarding.
Public SaaS terms overview and privacy information for customers, prospects and marketplace reviewers.
Preparation, not certificationAIDE Chain is not currently claiming certification to ISO/IEC 27001:2022 or coverage by a SOC 2 Type II report. The public assurance material documents the controls and evidence already available, the proposed scope and the remaining management-system and external-audit activities required to reach those outcomes.
The current platform already produces useful assurance evidence through MFA and role controls, explicit tenant scoping, PostgreSQL row-level-security policy tests, dependency/static/secret scanning, SBOM generation, release-integrity checks, hardened external connectors, monitoring, audit events and tested recovery processes. The next assurance stage is to formalise the surrounding ISMS/control operating model: policies, risk ownership, access and supplier reviews, incident/continuity exercises, evidence retention, internal audit, management review and independent certification/attestation.
Buyer / sponsor
Start with Solution Architecture, then Assurance Readiness and Government Buyers or Terms, followed by the Onboarding Process.
Security / assurance reviewer
Read Solution Architecture, Security & Assurance and ISO/IEC 27001 & SOC 2 Readiness. Together they describe the system boundary, implemented controls, recovery/monitoring evidence and remaining external-assurance work.
Sales / business development partner
Start with the Sales Playbook, then use Solution Architecture, Security & Assurance, Assurance Readiness and Integrations & Telemetry when the conversation moves into technical or procurement detail.
Delivery lead / PMO
Read Customer Onboarding, Operating Guide and Integrations & Telemetry.
Enterprise architect
Read Solution Architecture, then the Blueprint sections of the Operating Guide and Integrations & Telemetry.
Public documentation intentionally explains the platform design and customer process without publishing secrets or tenant-specific implementation details. The following remain inside authenticated AIDE or the controlled implementation/assurance process: connector credentials and tokens, customer tenant identifiers, private architecture evidence, project/programme content, detailed audit records, exports, reports, organisation branding artefacts, customer-specific network/security configuration, sensitive support diagnostics and non-public assurance evidence supplied under customer due-diligence arrangements.