AIDE ChainAIDE CHAIN · BLUEPRINT

SECURITY OVERVIEW

Designed for defensible enterprise delivery.

AIDE Chain provides a secure production baseline and a clear path to customer-specific controls, assurance and hosting requirements.

Included security baseline

Identity and access

TOTP multi-factor authentication, recovery codes, role-based capabilities and server-side organisation and project access checks.

Tenant isolation

Organisation-scoped PostgreSQL records, explicit authorisation policy and regression coverage for cross-tenant boundaries.

Evidence and audit

Audit events, intervention history, immutable discovery observations, correlation IDs and structured logs retain decision evidence.

Recovery

PostgreSQL point-in-time recovery and Blob version recovery are documented and tested as part of the operating model.

Deployment controls

GitHub Actions tests, controlled schema migrations, exact-version health verification and Azure Monitor telemetry support repeatable releases.

Data protection

Encrypted Azure services, private artefact containers and secure runtime configuration support the standard SaaS deployment.

Optional enterprise uplift

Customers can separately scope Azure Front Door and WAF, Key Vault references, managed identity, private endpoints, VNet integration, SIEM/SOC integration, dedicated environments, enhanced retention, identity-provider integration, penetration testing and assurance support.

Assurance boundary

AIDE Chain provides architecture, data-flow, control, deployment, recovery and test evidence for customer-led assurance. Customer-specific IRAP, certification, penetration testing and remediation are separately scoped and funded.

Discuss security requirements