Security & trust
Trust is something we evidence, not claim
Here is how Aureon controls access, models custody, and records audit evidence — and precisely which gates remain external.
Role-based access & tenant isolation
Every operator action is governed by role-based access control with tenant isolation. The API verifies the JWT signature and authorizes on each request — the client never enforces authority on its own.
Custody by design (multisig)
Aureon's custody model is designed around multisig approval. Production signing is disabled, and the PROD-9 custody gate stays closed until a real key ceremony and hardware evidence are in place.
Audit & evidence
Operator actions are recorded with correlation IDs; readiness and runtime truth are surfaced rather than asserted. Local proof manifests and reproducible checks back every status we publish.
Production gates that stay closed
Custody, external security audit, legal/compliance sign-off, and on-chain deployment are explicit gates. None are bypassed for appearance; the platform is production NO-GO until each is genuinely met.
What's proven vs external
The honest gate status
A green item is proven and currently healthy. Blocked and pending items are owner- or vendor-gated and remain closed.