Identity and access
TOTP multi-factor authentication, recovery codes, role-based capabilities and server-side organisation and project access checks.
SECURITY OVERVIEW
AIDE Chain provides a secure production baseline and a clear path to customer-specific controls, assurance and hosting requirements.
TOTP multi-factor authentication, recovery codes, role-based capabilities and server-side organisation and project access checks.
Organisation-scoped PostgreSQL records, explicit authorisation policy and regression coverage for cross-tenant boundaries.
Audit events, intervention history, immutable discovery observations, correlation IDs and structured logs retain decision evidence.
PostgreSQL point-in-time recovery and Blob version recovery are documented and tested as part of the operating model.
GitHub Actions tests, controlled schema migrations, exact-version health verification and Azure Monitor telemetry support repeatable releases.
Encrypted Azure services, private artefact containers and secure runtime configuration support the standard SaaS deployment.
Customers can separately scope Azure Front Door and WAF, Key Vault references, managed identity, private endpoints, VNet integration, SIEM/SOC integration, dedicated environments, enhanced retention, identity-provider integration, penetration testing and assurance support.
AIDE Chain provides architecture, data-flow, control, deployment, recovery and test evidence for customer-led assurance. Customer-specific IRAP, certification, penetration testing and remediation are separately scoped and funded.