Trust Center

Augur Trust Center

Everything we do to keep your fleet’s data safe. Built for the procurement teams and CISOs who run the security review.

Last reviewed · May 2026

Attestations

Where we are on the frameworks procurement asks about

Honest status, not aspirational. Certifications under way list the auditor engagement window; the rest list current alignment posture.

SOC 2 Type II
In progress

Auditor engaged Q3 2026 · observation window Q3 2026 → Q1 2027 · report Q2 2027.

ISO 27001
In progress

Gap assessment Q4 2026 · certification target 2027.

GDPR
Certified

EU data residency available · DPA on request · DPO contactable at privacy@enrevia-augur.com.

HIPAA-ready
Certified

Business Associate Agreement available · PHI never carried in telemetry by design.

CCPA
Certified

Consumer data-subject requests honoured within 45 days · "do not sell" by default.

CSA STAR
Roadmap

CAIQ self-assessment available now · STAR Level 1 submission planned post-SOC 2.

Security posture

The eight controls that anchor our security review

Each control is implemented and continuously regression-tested in CI. Detail beyond what fits on a marketing page lives in the security whitepaper below.

mTLS in transit

Every agent ↔ broker connection uses mutual TLS with per-tenant topic ACLs. Device A can’t see device B’s commands — and tenant A can’t see tenant B’s ACLs.

AES-256-GCM at rest

Every secret at rest — recovery keys, audit-export tokens, LLM provider API keys, IdP signing secrets — sealed with AES-256-GCM under a per-deployment master key.

scrypt password hashing

User passwords stored as scrypt hashes (N=16384, r=8, p=1) with a unique 16-byte salt per user. No reversible storage anywhere.

2-person rule

Wipes, mass uninstalls, bulk reboots — every destructive verb supports an N-of-N approval gate. Issuer cannot self-approve. Included on every tier, not gated.

Audit log retention

Append-only audit trail with 7-year retention by default. Every command, every approval, every policy change. SOC 2 CC7.2-aligned.

Audited tenant isolation

28 cross-tenant regression tests across 7 services. Identical "not found" wording on foreign-tenant access — IDs cannot be enumerated.

Code-signed agent

macOS notarised · Windows Authenticode · Linux packages signed with our public release key. The agent rejects updates it can’t verify.

Privacy by default

Telemetry is metadata only — never screen content, keystrokes, or file contents. The agent’s data model literally can’t carry PII.

Documents

Everything procurement asks for

Self-assessment artifacts now; third-party-attested reports once each audit closes. Drop us a note if you need a specific format.

  • SOC 2 readiness self-assessment
    Pre-audit self-attestation against the Trust Services Criteria. Pulled from docs/security/soc2-readiness.md.
    Download (coming soon)
  • Multi-tenant isolation audit
    Cross-tenant regression coverage report — the 28-test suite that gates every release.
    Download (coming soon)
  • Data Processing Agreement (DPA)
    Standard contractual clauses + Augur-specific data-handling commitments. Templated for fast counter-signature.
    Download (coming soon)
  • Security whitepaper
    End-to-end architecture review: agent, broker, control plane, ML pipeline, audit trail.
    Download (coming soon)
  • Penetration test summary
    Independent third-party penetration test summary. Pending engagement Q3 2026 alongside the SOC 2 observation window.
    Download (coming soon)
Sub-processors

Every third party that touches your data

The full list, with what each sub-processor is for and where the data sits. We notify customers 30 days before adding a sub-processor.

Sub-processorPurposeData sharedLocationDPA
Amazon Web ServicesPrimary cloud infrastructure (compute, storage, networking)All customer telemetry + control-plane dataus-east-2 · eu-west-1 (EU data residency)Signed
CrowdStrikeEDR signal ingestion (optional, customer-configured)Device-identifier mapping only · payload stays on the EDR sideUS · EU (per CrowdStrike tenant region)Standard
DatadogInternal infrastructure monitoring · APMAugur service-side metrics + logs (no customer device telemetry)US · EUSigned
GitHubSource-code hosting · CI/CDSource code · build artifacts · no customer dataUnited StatesSigned
AnthropicLLM provider — audit summarisation + anomaly triageAnonymised audit-log narratives · device IDs hashed before sendUnited StatesSigned

Subscribe to sub-processor change notifications at security@enrevia-augur.com.

All systems operational
Real-time uptime + historical incident timeline at status.enrevia-augur.com.
Visit status.enrevia-augur.com
Contact

Talk to security

Found something? Tell us. We respond to credible reports within one business day and credit researchers in our advisories.

Encrypted reports welcome. Our PGP key fingerprint is published under /.well-known/security.txt.

Procurement / DPA inbox
privacy@enrevia-augur.com

DPA counter-signature, sub-processor change subscriptions, and data-subject requests.

Submit a vulnerability report

We triage every report. Include reproduction steps + impact assessment if you can.