# ApertureRisks Security Controls Summary

Version: July 18, 2026

Operator: PWLogiConGroup LLC

Security contact: ian@pwlogicongroup.com

## Status statement

ApertureRisks has not completed SOC 2 or ISO 27001 certification, FedRAMP authorization, an independent penetration test, or an independent security audit. No certification, authorization, audit, penetration-test result, or third-party attestation is implied. This summary is not an uptime commitment, SLA, disaster-recovery guarantee, or substitute for a signed agreement.

No certification or active audit is claimed. Future independent attestations will be evaluated against customer and contractual requirements.

## Data handling and architecture boundary

- Public forms are for inquiry and scoping, not sensitive operational files.
- Operational records move only through an approved, engagement-specific intake path.
- Outputs label verified, contextual, inferred, unsupported, and missing evidence.
- Client data is not sold and is not shared with other clients.
- No public subprocessor list or standard DPA is currently represented as completed. Their availability and engagement-specific provider use must be confirmed during contracting before sensitive intake.

## Technical and administrative controls

- Application source and committed deployment-related files are version controlled. Runtime secrets and environment settings are managed separately in the deployment platform and are not represented as fully version controlled.
- OAuth and Coupa credential payloads are authenticated-encrypted with AES-256-GCM before persistence.
- OAuth state is signed, provider- and tenant-bound, and expires after ten minutes.
- Tenant connectors require explicit administrator enablement and fail closed.
- Email connector scope creates provider-native drafts; it does not authorize sending.
- Material agent preparation, approval, rejection, provider outcome, and failure events are stored in append-only database tables. This is not represented as a cryptographically chained ledger.
- Authenticated workflows enforce tenant context and role permissions.
- Recommendations remain subject to named human review before action.

## Retention, deletion, and exit

Retention is agreed by engagement, data category, and legal requirement before sensitive intake. The SOW or order form should state the retention period, authorized export format, return or deletion process, deletion confirmation requirement, and any legally required residual retention.

## Incident response and support

Current support hours are U.S. business days, 9:00 a.m.-5:00 p.m. Eastern Time. Security and tenant-isolation reports are treated as Critical until triaged, with a same-business-day initial-response target during the support window. No 24x7 support, uptime SLA, recovery-time commitment, or service credit is included unless signed in writing.

## Continuity and attestations

The current service is principal-led. Alternate staffing, extended incident coverage, escrow, backup-resource commitments, disaster-recovery capability, and recovery objectives are not implied and must be agreed in writing. SOC 2, ISO 27001, FedRAMP, an independent penetration test, an independent security audit, and formal third-party attestations have not been completed.

## Procurement documents

A security questionnaire response, DPA, subprocessor list, or data-flow discussion may be requested during qualified review, but availability is not guaranteed by this summary. The downloadable SOW template is nonbinding until completed and signed with the controlling agreement.
